← Back to KC filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
4.A.History and Development of the Company
Corporate History
In January 2012, we incorporated Kingsoft Cloud Holdings Limited under the laws of the Cayman Islands as our offshore holding company. In February 2012, we incorporated Kingsoft Cloud Corporation Limited as Kingsoft Cloud Holdings Limited’s wholly owned subsidiary in Hong Kong.
In April 2012, Kingsoft Cloud Corporation Limited incorporated Beijing Kingsoft Cloud Technology Co., Ltd., or Beijing Kingsoft Cloud, as its wholly owned subsidiary in the PRC. In December 2015, Kingsoft Cloud Corporation Limited incorporated another wholly owned subsidiary, Beijing Yunxiang Zhisheng Technology Co., Ltd., or Yunxiang Zhisheng, in the PRC.
In December 2017, Kingsoft Cloud Corporation Limited incorporated a wholly owned subsidiary, Kingsoft Cloud Inc., in the United States, to operate a cloud service business and conduct research and development on cloud technology and products.
In May 2020, we completed an initial public offering in which we offered and sold an aggregate of 517,500,000 ordinary shares in the form of ADSs. Upon the initial public offering, all of our issued and outstanding preferred shares were automatically converted into ordinary shares on a one-for-one basis. On May 8, 2020, the ADSs began trading on the Nasdaq under the symbol “KC.”
In September 2020, we completed a public offering in which we offered an aggregate of 9,250,000 ADSs and our selling shareholders sold an aggregate of 8,421,576 ADSs.
In March 2021, we completed the acquisition of 100% equity interest in Shenzhen Yunfan Acceleration Technology Co., Ltd. (currently named as “Kingsoft Cloud (Shenzhen) Edge Computing Technology Co., Ltd”) and its subsidiary (collectively, “Kingsoft Cloud Shenzhen”). Kingsoft Cloud Shenzhen is mainly engaged in providing content distribution, acceleration and other cloud-related IaaS and PaaS edge computing solutions, and the acquisition is expected to enhance our expertise in public cloud services.
In September 2021, we acquired controlling interests in Camelot Employee Scheme INC. (“Camelot”) using a combination of cash and our ordinary shares as consideration. In connection with such acquisition, we issued an aggregate of 247,475,446 ordinary shares to certain existing shareholders of Camelot in September 2021. In October 2022, we acquired 9.50% equity interests in Camelot for a total cash consideration of RMB456 million. In November 2022, we acquired 3.19% equity interest in Camelot using a combination of cash and our ordinary shares as consideration. Camelot offers comprehensive and digitalized solutions such as teller or branch systems, anti-money laundering and fraud prevention software services to the financial services industry. By acquiring and integrating with Camelot, we expect to benefit from its (i) core senior management’s rich experience; (ii) large customer based and long-standing client relationships to cross-sell our products and solutions; (iii) deep vertical know-how for developing industry solutions; and (iv) nationwide fulfillment centers across major cities in China for project deployment with lower costs with enhanced efficacy and increased customer stickiness.
In December 2021, we increased our authorized share capital from US$4,000,000.00 divided into 4,000,000,000 ordinary shares with par value of US$0.001 each to US$40,000,000.00 divided into 40,000,000,000 ordinary shares with par value of US$0.001 each by creation of an additional 36,000,000,000 authorized but unissued ordinary shares with par value of US$0.001 each.
In December 2022, we listed, by way of introduction, our ordinary shares on the Main Board of SEHK. The ordinary shares are traded on the Main Board of SEHK under the stock code “3896” in board lots of 2000 Shares, and the stock short name is “KINGSOFT CLOUD.”
In April 2025, we completed a public offering in which we offered an aggregate of (i) 20,075,000 ADSs (including the full exercise of the underwriters’ option to purchase additional ADSs), and (ii) 18,000,000 ordinary shares.
In September 2025, we completed a public offering in which we offered an aggregate of 338,000,000 ordinary shares.
69
Table of Contents
Beijing Kingsoft Cloud entered into a series of contractual arrangements, as amended and restated, with Zhuhai Kingsoft Cloud and its registered shareholders, through which we obtained control over Zhuhai Kingsoft Cloud. In addition, Yunxiang Zhisheng entered into a series of contractual arrangements with Kingsoft Cloud Information and its registered shareholders, which enable us to obtain control over the Kingsoft Cloud Information to operate value-added telecommunication services. The Company is obligated to absorb losses of the variable interest entities that could potentially be significant to the variable interest entities through providing unlimited financial support to the variable interest entities or is entitled to receive economic benefits from the variable interest entities that could potentially be significant to the variable interest entities through the exclusive technology consulting and service fees. As a result of these contractual arrangements, the Company is determined to be the primary beneficiary of these variable interest entities only for accounting purposes and we consolidate these variable interest entities under U.S. GAAP. We refer to Beijing Kingsoft Cloud and Yunxiang Zhisheng as our wholly foreign owned entities, or WFOEs, and to Zhuhai Kingsoft Cloud, Kingsoft Cloud Information and their subsidiaries as our variable interest entities, or the VIEs, in this annual report. For more details and risks related to the VIE structure, please see “Item 4. Information on the Company - 4.C. Organizational Structure - Contractual Arrangements with the VIEs and Their Respective Shareholders” and “Item 3. Key Information - 3.D. Risk Factors - Risks Relating to Our Corporate Structure and the Contractual Arrangements”.
Our principal executive offices are located at Building D, Xiaomi Science and Technology Park, No. 33 Xierqi Middle Road, Haidian District Beijing, 100085, the People’s Republic of China. Our telephone number at this address is +86 10 6292 7777. Our registered office in the Cayman Islands is located at the offices of Conyers Trust Company (Cayman) Limited, Cricket Square, Hutchins Drive, P.O. Box 2681, Grand Cayman KY1-1111, Cayman Islands. Our agent for service of process in the United States is Cogency Global Inc. located at 122 East 42nd Street, 18th Floor, New York, NY 10168.
The SEC maintains an internet site at http://www.sec.gov that contains reports, information statements and other information regarding issuers that file electronically with the SEC.
Contractual Arrangements and Corporate Structure
Current PRC laws and regulations impose certain restrictions or prohibitions on foreign ownership of companies that engage in value-added telecommunication services. We are an exempted company with limited liability incorporated in the Cayman Islands. Our PRC subsidiaries, Beijing Kingsoft Cloud and Yunxiang Zhisheng are considered foreign-invested enterprises. To comply with PRC laws and regulations, we primarily conduct our business in China through the VIEs, Zhuhai Kingsoft Cloud and Kingsoft Cloud Information, and their subsidiaries, based on a series of contractual arrangements. Through these contractual arrangements, the nominee shareholders of the VIEs effectively assigned all of their voting rights underlying their equity interests in the VIEs to the Company, and therefore, the Company has the power to direct the activities of the VIEs that most significantly impact its economic performance. The Company is obligated to absorb losses of the variable interest entities that could potentially be significant to the variable interest entities through providing unlimited financial support to the variable interest entities or is entitled to receive economic benefits from the variable interest entities that could potentially be significant to the variable interest entities through the exclusive technology consulting and service fees. As a result of these contractual arrangements, the Company is determined to be the primary beneficiary of these variable interest entities only for accounting purposes and we consolidate these variable interest entities under U.S. GAAP. These contractual arrangements entered into with the VIEs enable us to (i) receive substantially all of the economic benefits and absorb substantially all of the economic losses of the VIEs, and (ii) have an exclusive option to purchase all or part of the equity interests and assets in the VIEs when and to the extent permitted by PRC law. These contractual arrangements include the exclusive consultation and technical service agreements, loan agreements, equity pledge agreements, exclusive purchase option agreements, shareholder voting right trust agreements, and spousal consents, as the case may be. As a result of these contractual arrangements, we are considered the primary beneficiary of the VIEs for accounting purpose and consolidate its operating results in our financial statements under U.S. GAAP, to the extent the conditions for the consolidation of the VIE under U.S. GAAP are satisfied.
We do not have any equity interests in the VIEs who is owned by certain nominee shareholders. As a result, control through these contractual arrangements may be less effective than direct ownership, and we could face heightened risks and costs in enforcing these contractual arrangements, because there are substantial uncertainties regarding the interpretation and application of current and future PRC laws, regulations, and rules relating to the legality and enforceability of these contractual arrangements. If the PRC government finds such agreements to be illegal, we could be subject to severe penalties or be forced to relinquish our interests in the VIEs.
70
Table of Contents
Permits and Permission Required from the PRC Authorities for Our Operations
Our PRC subsidiaries and the VIEs have obtained all material licenses and approvals required for our operations in China. Given the uncertainties of interpretation and implementation of relevant laws and regulations and the enforcement practice by relevant government authorities, we may be required to obtain additional licenses, permits, filings, or approvals for our business operations in the future. If we, our PRC subsidiaries or VIE are found to be in violation of any existing or future PRC laws or regulations, or fail to obtain or maintain any of the required permits, approvals or filings, the relevant PRC regulatory authorities would have discretion to take action in dealing with such violations or failures. In addition, if we had inadvertently concluded that such approvals, permits, registrations or filings were not required, or if applicable laws, regulations or interpretations change in a way that requires us to obtain such approval, permits, registrations or filings in the future, we and the VIE may be unable to obtain such necessary approvals, permits, registrations or filings in a timely manner, or at all, and such approvals, permits, registrations or filings may be rescinded even if obtained. Any such circumstance may subject us to fines and other regulatory, civil or criminal liabilities, and we may be ordered by the competent government authorities to suspend relevant operations, which will materially and adversely affect our business operation. Furthermore, we may be subject to regular inspections, examinations, inquiries or audits by regulatory authorities, and an adverse outcome of such inspections, examinations, inquiries or audits may result in the loss or non-renewal of the relevant licenses and approvals. Moreover, the criteria used in reviewing applications for, or renewals of licenses and approvals may change from time to time, and there can be no assurance that we will be able to meet new criteria that may be imposed to obtain or renew the necessary licenses and approvals. Many of such licenses and approvals are material to the operation of our business, and if we fail to maintain or renew material licenses and approvals, our ability to conduct our business could be materially impaired. Furthermore, if the interpretation or implementation of existing laws and regulations change, or new regulations come into effect, requiring us or parties on whom we rely to obtain any additional permits, licenses or certificates that were previously not required to operate our business, there can be no assurance that we or parties on whom we rely will successfully obtain such permits, licenses or certificates.
Transfer of Funds and Other Assets
Under relevant PRC laws and regulations, we are permitted to remit funds to the VIEs through loans rather than capital contributions.
In 2025, Kingsoft Cloud Holdings Limited and its subsidiaries made capital contribution amounted to RMB80.8 million (US$11.5 million) to the WFOEs. Beijing Kingsoft Cloud and Yunxiang Zhisheng, our PRC subsidiaries, provided the VIEs and their subsidiaries with technical support, consulting services and other services related to the business of VIEs and their subsidiaries, including business management, daily operations, strategic planning, among others.
As of December 31, 2024 and 2025, there were no outstanding balance owed by the VIEs to Kingsoft Cloud Holdings Limited and its subsidiaries under the VIE agreements, and there were no outstanding balance owed by Kingsoft Cloud Holdings Limited and its subsidiaries to the VIEs under the VIE agreements. In 2025, Kingsoft Cloud Holdings Limited and its subsidiaries provided loans amounted to RMB2,636.6 million (US$377.0 million) to the VIEs and repaid loans amounted to RMB100.0 (US$14.3 million), and the VIEs provided loans amounted to RMB50.0 million (US$7.1 million) to Kingsoft Cloud Holdings Limited and its subsidiaries. In 2025, the VIEs transferred RMB33.1 million (US$4.7 million) to our PRC subsidiaries for services provided. There were no other assets transferred between the VIEs and their subsidiaries and non-VIEs in 2025. For any amounts owed by the VIEs to Kingsoft Cloud Holdings Limited or our PRC subsidiaries under the contractual arrangements with the VIEs, unless otherwise required by PRC tax authorities, we are able to settle such amounts under the current effective PRC laws and regulations, provided that the VIEs have sufficient funds to do so.
Kingsoft Cloud Holdings Limited has not previously declared or paid any cash dividend or dividend in kind, and has no plan to declare or pay any dividends in the near future on our shares or the ADSs representing our ordinary shares. None of the VIEs or our PRC subsidiaries has issued any dividends or distributions to their respective parent companies, including Kingsoft Cloud Holdings Limited, or to any investors as of the date of this annual report. We currently intend to retain most, if not all, of our available funds and any future earnings to operate and expand our business. See “Item 8. Financial Information—8.A. Consolidated Statements and Other Financial Information—Dividend Policy.”
71
Table of Contents
For the purpose of illustration, the below table reflects the hypothetical taxes that might be required to be paid within China, assuming that: (i) we have taxable earnings, and (ii) we determine to pay a dividend in the future:
Taxation Scenario (1)
Statutory Tax and Standard Rates
Hypothetical pre-tax earnings(2) 100 %
Tax on earnings at statutory rate of 25% (25) %
Net earnings available for distribution 75 %
Withholding tax at standard rate of 10%(3) (7.5) %
Net distribution to Kingsoft Cloud Holdings Limited/Shareholders 67.5 %
Notes:
(1) The tax calculation has been simplified for the purpose of this example. The hypothetical book pre-tax earnings amount, which does not consider timing differences, is assumed to equal the taxable income in the PRC.
(2) Under the terms of the VIE agreements, sales service fees are charged by our PRC subsidiaries to the VIEs and their subsidiaries. For all the periods presented, these fees are recognized as cost of revenues of the VIEs and their subsidiaries with a corresponding amount as service income by our PRC subsidiaries and eliminated in consolidation. For income tax purposes, our PRC subsidiaries, VIEs and their subsidiaries file income taxes on a separate company basis. The fees paid are recognized as a tax deduction by the VIEs and their subsidiaries and as income by our PRC subsidiaries and are tax neutral. Upon the instance that the VIEs and their subsidiaries reach a cumulative level of profitability, because our PRC subsidiaries occupy certain trademarks and copyrights, the agreements will be updated to reflect charges for such trademarks and copyrights usage on the basis that they will qualify for tax neutral treatment.
(3) China’s Enterprise Income Tax Law imposes a withholding income tax of 10% on dividends distributed by a Foreign Invested Enterprises (“FIE”) to its immediate holding company outside of China. A lower withholding income tax rate of 5% is applied if the FIE’s immediate holding company is registered in Hong Kong or other jurisdictions that have a tax treaty arrangement with China, subject to a qualification review at the time of the distribution. For the purpose of this hypothetical example, this table has been prepared based on a taxation scenario under which the full withholding tax would be applied.
The table above has been prepared under the assumption that all profits of the VIEs and their subsidiaries will be distributed as fees to our PRC subsidiaries under tax neutral contractual arrangements. If in the future, the accumulated earnings of the VIEs and their subsidiaries exceed the fees paid to our PRC subsidiaries, or if the current and contemplated fee structure between the intercompany entities is determined to be non-substantive and disallowed by Chinese tax authorities, we have other tax-planning strategies that can be deployed on a tax neutral basis.
Should all tax planning strategies fail, the VIEs and their subsidiaries could, as a matter of last resort, make a non-deductible transfer to our PRC subsidiaries for the amounts of the stranded cash in the VIEs and their subsidiaries. This would result in the double taxation of earnings: one at the VIE level (for non-deductible expenses) and one at the PRC subsidiary level (for presumptive earnings on the transfer). Such a transfer and the related tax burdens would reduce our after-tax income to approximately 50.63% of the pre-tax income. Our management is of the view that the likelihood that this scenario would happen is remote.
72
Table of Contents
Condensed Consolidating Schedule
The following tables present the summary statements of operations for Kingsoft Cloud Holdings Limited, its WFOE, its subsidiaries other than WFOE, and the VIEs and their subsidiaries for the periods presented.
For the Year Ended December 31, 2023
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Third-party revenues — — 2,891,095 4,156,366 — 7,047,461
Intra-Group revenues (1) — 14,655 31,054 443,355 (489,064) —
Total revenues — 14,655 2,922,149 4,599,721 (489,064) 7,047,461
Third-party costs and expenses (36,736) (262,123) (2,594,523) (6,262,630) — (9,156,012)
Intra-Group costs and expenses (1) — — (320,354) (39,695) 360,049 —
Total costs and expenses (36,736) (262,123) (2,914,877) (6,302,325) 360,049 (9,156,012)
Operating (loss) income (36,736) (247,468) 7,272 (1,702,604) (129,015) (2,108,551)
(Loss) income from non-operations (18,205) 274,356 67,576 (407,418) 8,595 (75,096)
Share of income of subsidiaries 62,514 — — — (62,514) —
Contractual interests in VIEs and VIEs’ subsidiaries (3) (2,183,913) — — — 2,183,913 —
Net (loss) income (2,176,340) 26,888 74,848 (2,110,022) 2,000,979 (2,183,647)
73
Table of Contents
For the Year Ended December 31, 2024
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Third-party revenues — — 2,947,497 4,837,683 — 7,785,180
Intra-Group revenues (1) — 12,991 21,126 365,009 (399,126) —
Total revenues — 12,991 2,968,623 5,202,692 (399,126) 7,785,180
Third-party costs and expenses (25,975) (109,775) (2,821,439) (6,567,001) — (9,524,190)
Intra-Group costs and expenses (1) — (25,494) (223,181) (42,134) 290,809 —
Total costs and expenses (25,975) (135,269) (3,044,620) (6,609,135) 290,809 (9,524,190)
Operating loss (25,975) (122,278) (75,997) (1,406,443) (108,317) (1,739,010)
(Loss) income from non-operations (28,733) 205,632 153,443 (506,601) (63,773) (240,032)
Share of income of subsidiaries 1,072 — — — (1,072) —
Contractual interests in VIEs and VIEs’ subsidiaries (3) (1,913,044) — — — 1,913,044 —
Net (loss) income (1,966,680) 83,354 77,446 (1,913,044) 1,739,882 (1,979,042)
For the Year Ended December 31, 2025
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Third-party revenues — 36,275 3,120,734 6,401,610 — 9,558,619
Intra-Group revenues (1) — 7,223 53,486 218,763 (279,472) —
Total revenues — 43,498 3,174,220 6,620,373 (279,472) 9,558,619
Third-party costs and expenses (51,962) (137,362) (3,311,367) (6,830,841) — (10,331,532)
Intra-Group costs and expenses (1) — (783) (79,557) (61,489) 141,829 —
Total costs and expenses (51,962) (138,145) (3,390,924) (6,892,330) 141,829 (10,331,532)
Operating loss (51,962) (94,647) (216,704) (271,957) (137,643) (772,913)
(Loss) income from non-operations (3,626) 260,158 49,456 (496,139) 19,372 (170,779)
Share of loss of subsidiaries (112,568) — — — 112,568 —
Contractual interests in VIEs and VIEs’ subsidiaries (3) (768,095) — — — 768,095 —
Net (loss) income (936,251) 165,511 (167,248) (768,096) 762,392 (943,692)
74
Table of Contents
The following tables present the summary balance sheet data for Kingsoft Cloud Holdings Limited, its WFOE, its subsidiaries other than WFOE, and the VIEs and their subsidiaries as of the dates presented.
As of December 31, 2024
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Current assets:
Cash and cash equivalents 4,843 295,430 1,180,814 1,167,677 — 2,648,764
Restricted cash — — 35,837 45,500 — 81,337
Accounts receivable, net — — 424,004 1,044,659 — 1,468,663
Short-term investment — — 90,422 — — 90,422
Prepayments and other assets 31,216 16,003 865,549 1,320,306 — 2,233,074
Amounts due from related parties — 232 51,902 266,392 — 318,526
Total current assets 36,059 311,665 2,648,528 3,844,534 — 6,840,786
Non-current assets:
Property and equipment, net — 43,098 52,436 4,534,518 — 4,630,052
Intangible assets, net — — 620,773 74,107 — 694,880
Prepayments and other assets — — 1,061 448,922 — 449,983
Goodwill — — 4,556,909 48,815 — 4,605,724
Equity investments — 17,197 50,871 166,114 — 234,182
Investments in subsidiaries (2) 6,064,318 — — — (6,064,318) —
Operating lease right-of-use assets — 2,105 39,990 94,952 — 137,047
Total non-current assets 6,064,318 62,400 5,322,040 5,367,428 (6,064,318) 10,751,868
Amounts due from Kingsoft Cloud Holdings Limited — 5,457 1,269,233 86,275 (1,360,965) —
Amounts due from subsidiaries (other than WFOE) — 2,690 — 2,658,342 (2,661,032) —
Amounts due from WFOE — — 1,163,360 613,455 (1,776,815) —
Amounts due from VIEs and VIEs’ subsidiaries — 9,623,511 3,595,806 — (13,219,317) —
Amounts due from group companies — 9,631,658 6,028,400 3,358,071 (19,018,129) —
Total assets 6,100,377 10,005,723 13,998,968 12,570,033 (25,082,447) 17,592,654
Current liabilities:
Accounts payable — — 166,267 1,710,737 — 1,877,004
Accrued expenses and other liabilities 837,703 79,254 934,439 1,490,594 — 3,341,990
Short-term bank loans — — 59,500 2,166,265 — 2,225,765
Income tax payable 2,902 — 66,317 — — 69,219
Amounts due to related parties — 29,354 50,191 1,504,654 — 1,584,199
Current operating lease liabilities — 2,161 18,768 40,329 — 61,258
Total current liabilities 840,605 110,769 1,295,482 6,912,579 — 9,159,435
Non-current liabilities:
Long-term bank loan — — — 1,660,584 — 1,660,584
Deferred tax liabilities — 12,063 89,614 — — 101,677
Other liabilities — — 69,189 721,082 — 790,271
Non-current operating lease liabilities — — 16,403 49,352 — 65,755
Amounts due to related parties — — — 309,612 — 309,612
Total non-current liabilities — 12,063 175,206 2,740,630 — 2,927,899
Amounts due to Kingsoft Cloud Holdings Limited — — — — — —
Amounts due to subsidiaries (other than WFOE) 1,269,233 1,163,360 — 3,595,806 (6,028,400) —
Amounts due to WFOE 5,457 — 2,690 9,623,511 (9,631,658) —
Amounts due to VIEs and VIEs’ subsidiaries 86,275 613,454 2,658,342 — (3,358,071) —
Amounts due to group companies 1,360,965 1,776,814 2,661,032 13,219,317 (19,018,129) —
Total liabilities 2,201,570 1,899,646 4,131,720 22,872,526 (19,018,129) 12,087,334
75
Table of Contents
For the Year Ended December 31, 2025
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Current assets:
Cash and cash equivalents 2,161,778 145,216 2,341,159 1,369,890 — 6,018,043
Restricted cash — — 50,088 49,106 — 99,194
Accounts receivable, net — 1,656 433,281 1,305,535 — 1,740,472
Prepayments and other assets 4,633 6,783 871,067 1,709,831 — 2,592,314
Amounts due from related parties — 694 130,748 441,954 — 573,396
Total current assets 2,166,411 154,349 3,826,343 4,876,316 — 11,023,419
Non-current assets:
Property and equipment, net — 93,952 51,610 9,949,308 — 10,094,870
Intangible assets, net — — 467,840 64,929 — 532,769
Prepayments and other assets — 50 300 139,486 — 139,836
Goodwill — — 4,556,909 48,815 — 4,605,724
Equity investments — 18,433 49,619 166,114 — 234,166
Investments in subsidiaries (2) 5,881,741 — — — (5,881,741) —
Operating lease right-of-use assets — 539 31,645 66,221 — 98,405
Total non-current assets 5,881,741 112,974 5,157,923 10,434,873 (5,881,741) 15,705,770
Amounts due from Kingsoft Cloud Holdings Limited — 36,038 — 46,987 (83,025) —
Amounts due from subsidiaries (other than WFOE) 1,478,929 4,350 — 1,509,834 (2,993,113) —
Amounts due from WFOE — — 1,072,986 794,180 (1,867,166) —
Amounts due from VIEs and VIEs’ subsidiaries — 9,266,269 3,687,510 — (12,953,779) —
Amounts due from group companies 1,478,929 9,306,657 4,760,496 2,351,001 (17,897,083) —
Total assets 9,527,081 9,573,980 13,744,762 17,662,190 (23,778,824) 26,729,189
Current liabilities:
Accounts payable — — 197,368 1,817,085 — 2,014,453
Accrued expenses and other liabilities 127,030 136,702 971,740 1,986,957 — 3,222,429
Short-term bank loans — — 40,643 3,307,636 — 3,348,279
Income tax payable — — 73,310 — — 73,310
Amounts due to related parties — 29,318 754 691,860 — 721,932
Current operating lease liabilities — 273 20,723 19,945 — 40,941
Total current liabilities 127,030 166,293 1,304,538 7,823,483 — 9,421,344
Non-current liabilities:
Long-term bank loan — — — 3,023,538 — 3,023,538
Deferred tax liabilities — 12,063 49,851 — — 61,914
Other liabilities — — 75,408 2,570,487 — 2,645,895
Non-current operating lease liabilities — 248 6,289 44,602 — 51,139
Amounts due to related parties — — — 2,212,325 — 2,212,325
Total non-current liabilities — 12,311 131,548 7,850,952 — 7,994,811
Amounts due to Kingsoft Cloud Holdings Limited — — 1,478,929 — (1,478,929) —
Amounts due to subsidiaries (other than WFOE) — 1,072,986 — 3,687,510 (4,760,496) —
Amounts due to WFOE 36,038 — 4,350 9,266,269 (9,306,657) —
Amounts due to VIEs and VIEs’ subsidiaries 46,987 794,180 1,509,834 — (2,351,001) —
Amounts due to group companies 83,025 1,867,166 2,993,113 12,953,779 (17,897,083) —
Total liabilities 210,055 2,045,770 4,429,199 28,628,214 (17,897,083) 17,416,155
76
Table of Contents
The following tables present the summary cash flow data for Kingsoft Cloud Holdings Limited, its WFOE, its subsidiaries other than WFOE, and the VIEs and their subsidiaries for the periods presented.
For the Year Ended December 31, 2023
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Net cash (used in) generated from operating activities (66,850) (108,442) 292,797 (286,575) — (169,070)
Net cash generated from (used in) investing activities 609,277 (1,557,071) (181,347) (1,833,636) 2,289,591 (673,186)
Net cash (used in) generated from financing activities (681,660) 1,341,798 (408,198) 1,809,799 (2,289,591) (227,852)
For the Year Ended December 31, 2024
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Net cash (used in) generated from operating activities (82,174) (141,793) 440,084 412,302 — 628,419
Net cash generated from (used in) investing activities 243,994 (94,984) (1,217,741) (3,036,703) 484,989 (3,620,445)
Net cash (used in) generated from financing activities (213,174) 431,319 640,536 2,881,726 (484,989) 3,255,418
For the Year Ended December 31, 2025
Kingsoft
Cloud Subsidiaries VIEs and
Holdings (other than their
Limited WFOE WFOE) subsidiaries Eliminations Consolidated
(RMB in thousands)
Net cash generated from (used in) operating activities 73,443 (366,140) 1,573,990 2,519,735 — 3,801,028
Net cash (used in) generated from investing activities (1,883,988) 135,135 185,680 (4,532,128) 1,565,572 (4,529,729)
Net cash generated from (used in) financing activities 4,031,637 80,791 (551,573) 2,187,700 (1,565,572) 4,182,983
Notes:
(1)It represents the intra-group transaction charge under a series of commercial agreements among the Company’s WFOE, subsidiaries, VIEs and VIEs’ subsidiaries.
(2)It represents the Company’s investments in Camelot, the Company’s subsidiaries.
(3)It represents the primary beneficiary’s share of loss generated from the VIEs and their subsidiaries.
Restrictions on Foreign Exchange and the Ability to Transfer Cash between Entities, Across Borders and to U.S. Investors
Kingsoft Cloud Holdings Limited’s ability to pay dividends, if any, to its shareholders and ADS holders and to service any debt it may incur will depend upon dividends paid by our PRC subsidiaries. Under PRC laws and regulations, our PRC subsidiaries are subject to certain restrictions with respect to paying dividends or otherwise transferring any of their net assets offshore to Kingsoft Cloud Holdings Limited. In particular, under the current effective PRC laws and regulations, dividends may be paid only out of distributable profits. Distributable profits are the net profit as determined under PRC GAAP, less any recovery of accumulated losses and appropriations to statutory and other reserves required to be made. Each of our PRC subsidiaries is required to set aside at least 10% of its after-tax profits each year, after making up previous years’ accumulated losses, if any, to fund certain statutory reserve funds, until the aggregate amount of such a fund reaches 50% of its registered capital. As a result, our PRC subsidiaries may not have sufficient distributable profits to pay dividends to us in the near future.
77
Table of Contents
Furthermore, if certain procedural requirements are satisfied, the payment of current account items, including profit distributions and trade and service related foreign exchange transactions, can be made in foreign currencies without prior approval from State Administration of Foreign Exchange (the “SAFE”) or its local branches. However, where RMB is to be converted into foreign currency and remitted out of China to pay capital expenses, such as the repayment of loans denominated in foreign currencies, approval from or registration with competent government authorities or its authorized banks is required. The PRC government may take measures at its discretion from time to time to restrict access to foreign currencies for current account or capital account transactions. If the foreign exchange control system prevents us from obtaining sufficient foreign currencies to satisfy our foreign currency demands, we may not be able to pay dividends in foreign currencies to our offshore intermediary holding companies or ultimate parent company, and therefore, our shareholders or investors in the ADSs. Further, we cannot assure you that new regulations or policies will not be promulgated in the future, which may further restrict the remittance of RMB into or out of the PRC. We cannot assure you, in light of the restrictions in place, or any amendment to be made from time to time, that our current or future PRC subsidiaries will be able to satisfy their respective payment obligations that are denominated in foreign currencies, including the remittance of dividends outside of the PRC. If any of our subsidiaries incurs debt on its own behalf in the future, the instruments governing such debt may restrict its ability to pay dividends to Kingsoft Cloud Holdings Limited. In addition, our PRC subsidiaries are required to make appropriations to certain statutory reserve funds, which are not distributable as cash dividends except in the event of a solvent liquidation of the companies.
For PRC and United States federal income tax consideration of an investment in the ADSs, see “Item 10. Additional Information—10.E. Taxation.”
Implication of the Holding Foreign Companies Accountable Act
Trading in our securities on U.S. markets, including the Nasdaq, may be prohibited under the Holding Foreign Companies Accountable Act (the “HFCAA”) if the PCAOB determines that it is unable to inspect or investigate completely our auditor for two consecutive years. On December 16, 2021, the PCAOB issued the HFCAA Determination Report to notify the SEC of its determinations that the PCAOB was unable to inspect or investigate completely registered public accounting firms headquartered in Chinese Mainland and Hong Kong (the “2021 Determinations”), including our auditor. The inability of the PCAOB to conduct inspections in the past also deprived our investors of the benefits of such inspections. On December 15, 2022, the PCAOB announced that it was able to conduct inspections and investigations completely of PCAOB-registered public accounting firms headquartered in Chinese Mainland and Hong Kong in 2022. The PCAOB vacated its previous 2021 Determinations accordingly. As a result, we were not at risk of having our securities subject to a trading prohibition under the HFCAA unless a new determination is made by the PCAOB. However, whether the PCAOB will continue to conduct inspections and investigations completely to its satisfaction of PCAOB-registered public accounting firms headquartered in Chinese Mainland and Hong Kong is subject to uncertainty and depends on a number of factors out of our, and our auditor’s, control, including positions taken by authorities of the PRC. The PCAOB is expected to continue to demand complete access to inspections and investigations against accounting firms headquartered in Chinese Mainland and Hong Kong in the future and states that it has already made plans to resume regular inspections going forward. The PCAOB is required under the HFCAA to make its determination on an annual basis with regards to its ability to inspect and investigate completely accounting firms based in the Chinese Mainland and Hong Kong. The possibility of being a “Commission-Identified Issuer” and risk of delisting could continue to adversely affect the trading price of our securities. If the PCAOB determines in the future that it no longer has full access to inspect and investigate accounting firms headquartered in Chinese Mainland and Hong Kong and we continue to use such accounting firm to conduct audit work, we would be identified as a “Commission-Identified Issuer” under the HFCAA following the filing of the annual report for the relevant fiscal year, and if we were so identified for two consecutive years, trading in our securities on U.S. markets would be prohibited. For details, see “Item 3. Key Information—3.D. Risk Factors—Risks Relating to Doing Business in China—Trading in our securities on U.S. markets, including the Nasdaq, may be prohibited under the Holding Foreign Companies Accountable Act, or the HFCAA, if the PCAOB determines that it is unable to inspect or investigate completely our auditor for two consecutive years.”
78
Table of Contents
4.B.Business Overview
Our Mission
Our mission is to become customers’ trusted partner to embrace digitalization.
Overview
We offer various cloud services to customers in strategically selected verticals. We help customers achieve digitalization and intelligent upgrade through our extensive cloud infrastructure, advanced cloud products based on our vigorous cloud technology R&D capabilities, industry-specific solutions and end-to-end fulfillment and deployment covering all project stages for customers.
We have established our market presence by addressing customers’ comprehensive needs. We provide various advanced cloud products primarily consisted of unified IaaS infrastructure, PaaS middleware, certain SaaS applications and AI solutions, which support a wide range of use cases that enable our customers’ diverse business objectives. We also offer our solutions in a holistic approach by merging our cloud solutions with dedicated customer services. Our end-to-end customer services cover planning, solution development, fulfillment and deployment, as well as ongoing maintenance and upgrade. The entire process is primarily executed by our in-house professionals, with strict adherence to high standards and full accountability.
We have strategically expanded our footprints into selected verticals and have established a strong market presence in each selected vertical through efficient execution. As we continue to complete featured projects with vertical leaders, we have accumulated proprietary industry know-how and formed in-depth view of each selected vertical, which enables us to provide high-quality industry-specific cloud solutions. We have also aligned our research and development efforts with our business focuses, which enables us to act swiftly and develop new product modules and features that are specifically tailored to address a growing number of business needs faced by our customers.
We implement a premium customer strategy, focusing on covering leading enterprises in selected verticals to establish market presence efficiently, with a customer-centric service philosophy. We have amassed a large and solid Premium Customer base with increasing spending. In 2023, 2024 and 2025, we had a total of 486, 492 and 473 Premium Customers, respectively.
Our revenue increased by 10.5% from RMB7,047.5 million in 2023 to RMB7,785.2 million in 2024, and further increased by 22.8% to RMB9,558.6 million (US$1,366.9 million) in 2025. The increase in 2025 was primarily due to expansion of our AI-related business..
Our Cloud Platform
We are dedicated to providing high-quality cloud solutions to businesses and organizations across various sectors. We have built a cloud platform consisting of extensive cloud infrastructure, advanced cloud-native products, industry-specific solutions, and end-to-end services. Cloud infrastructure is the foundation of our cloud platform. It consists of hardware, software components and network resources that are needed to support the delivery of cloud products, primarily as public cloud services, to customers. Leveraging our cloud infrastructure, we provide various advanced cloud products that can be utilized to design different solutions to meet various business needs. We have designed various industry-specific solutions which consist of a selection of cloud products to cater to customer demands across different industries. Instead of merely providing cloud solutions to facilitate the entire cloud adoption process, we also offer end-to-end fulfillment and deployment services, ranging from planning, solution development, fulfillment and deployment, as well as ongoing maintenance and upgrade.
79
Table of Contents
The following chart illustrates our cloud platform:
· Extensive cloud infrastructure. We have established extensive cloud infrastructure which is the foundation of our cloud platform. As of December 31, 2025, we had approximately 101,500 servers, and achieved exabyte-level (which equals to 1,000,000,000 gigabytes) storage capacity.
● Advanced cloud-native products. Our cloud is architected specifically for customers to run business in an elastic and distributed manner required in disruptive business models. We, as an early mover in serving internet customers, have cultivated proprietary cloud-native technology and have successfully commercialized our technology capabilities through advanced cloud products.
● Industry-specific solutions. Based on the variety of cloud products, we have designed various industry-specific solutions that can unleash the full potential of our infrastructure resources and add value to our customers. Leveraging our profound industry insights, we have strategically expanded our footprints into selected verticals and have established market presence through dedicated execution.
● End-to-end fulfillment and deployment. We serve our clients throughout the whole cloud adoption process. At project initiation, we provide planning services with in-depth industry know-how, setting the overarching route for cloud migration. We have customized procedures to help customer to smoothly migrate their mission-critical data and applications on to our cloud platform. With our in-house fulfillment and deployment professionals, we adhere to consistent high standards at every stage of cloud adoption and commit to quality deployment.
Our Products and Solutions
Our Public Cloud Products
Our public cloud products provide on-demand high-performance IT infrastructure resources, offering advantages such as agility, scalability and flexibility. Compared with traditional IT infrastructure, our public cloud products enable rapid adaptation to customers’ business needs without substantial investment in hardware. The public cloud products we offer include elastic computing, cloud storage, cloud network, cloud databases, big data and Starflow (“Xingliu”) Platform, a one-stop platform for training, inference, model service and agent service.
80
Table of Contents
Cloud Elastic Computing
Our cloud elastic computing products primarily include:
· Kingsoft Cloud Elastic Compute (“KEC”) Cloud Server: KEC is a core component of Kingsoft Cloud’s computing infrastructure, offering simple, efficient, secure, and highly scalable computing services. It enables users to perform large- scale internet computing, deploy required server environments, and easily adjust resources based on business needs. Compared to physical servers, KEC offers greater flexibility, security, and cost efficiency with a pay-as-you-go model. It eliminate the need for hardware procurement and allow on-demand elastic resource allocation, effectively improving O&M efficiency and reducing usage costs. KEC provides various instance types tailored for different industries and scenarios, including Standard, General-purpose, IO- optimized, Compute-optimized, Performance-ensured, and Galaxy series. With an availability of up to 99.975%, KEC supports seamless failover migration and the stability of user services. Upgrading with the latest hardware technology iterations in the industry, KEC is now fully compatible with Intel’s latest 6th-generation Xeon CPUs and AMD Turin platforms.
● Kingsoft Cloud GPU Cloud Server provides general-purpose GPU-accelerated computing, supporting applications such as scientific computing, image rendering, and GPU-based audio and video encoding and decoding. It offers users stable, fast, and flexible computing services, along with a unified and convenient cloud server management experience. Typical use cases for GPU Cloud Server (GEC) include offline training and online inference. Leveraging the powerful computing capabilities of GPUs, GEC serves as a comprehensive platform for training and inference. Additionally, it can be integrated with Kingsoft Cloud Object Storage (KS3) for cloud storage, Kingsoft Cloud Relational Database Service (KRDS) for online database services, and Kingsoft Cloud MapReduce (KMR) for large-scale distributed processing. This enables users to build a fully functional deep learning system, facilitating efficient and secure model training and online service deployment.
● Kingsoft Cloud Dedicated Host (“KDH”): For users with strong demands for on-premise resource allocation, security and compliance, we offer KDH to provide exclusive physical server resources. Users can create custom-configured dedicated cloud servers on the KDH and apply advanced virtualization technology to achieve resource exclusivity and security, and meet compliance requirements. The features of KDH primarily include resource isolation, custom configuration, flexible creation, adjustable configurations and graphical resource management control.
· Kingsoft Cloud Bare Metal Servers Elastic Physical Compute (“EPC”): EPC provides users with cloud-based dedicated and securely isolated physical server clusters, featuring physical-server level, high stability and excellent computing performance, with no CPU contention or virtualization performance overhead. Standard model can be deployed and delivered in a minimum of 30 minutes. Leveraging Kingsoft Cloud’s foundational capabilities such as Virtual Private Cloud, load balancing, operation and maintenance monitoring, and security protection, these servers integrate seamlessly with the full portfolio of cloud products including cloud databases and big data services, enabling convenient and efficient network deployment and server O&M.
81
Table of Contents
On the basis of the above advantages, GPU bare metal servers further incorporate powerful GPU computing power, delivering exceptional parallel computing and floating-point computing capabilities and supporting full-lifecycle management in the cloud. They are widely applicable to scenarios including AI deep learning, image rendering, cloud gaming, and AR/VR, providing users with stable, efficient, elastically scalable computing services to drive business innovation and rapid growth.
· Kingsoft Cloud Auto Scaling (“AS”): AS automatically adjusts the computing resources of KEC based on user-defined policies, enabling optimal and efficient utilization of cloud server resources that align with dynamic changes in user business needs. AS automatically reduces cloud servers to save resources and costs when the business demands decrease, and automatically increases cloud servers to ensure smooth and healthy business operations during the peak demand periods, preventing server crashes due to sudden spikes in workload and providing buffer time for issue resolution. Meanwhile, AS enhances transparency in the scaling process by introducing comprehensive lifecycle management and observability capabilities. It supports the parallel execution of multiple scaling trigger mechanisms to improve the efficiency and stability of auto-scaling. In addition, it provides lifecycle hook capabilities, allowing users to orchestrate and intervene in the scaling process to meet the demands of more complex business scenarios. Overall, it boasts such core advantages as automated deployment, cost optimization, high availability assurance, and flexible scalability. Kingsoft Cloud Container Engine (“KCE”): KCE is a high-performance intelligent computing container platform with containers at its core, which developed and adapted based on the native Kubernetes to seamlessly integrate containers with other basic computing, storage and network resources, products and services we offer. Built-in end-to-end tools for AI scenarios, KCE helps customers build elastic, highly available enterprise-level Kubernetes intelligent computing clusters with one click. It features with advantages such as security and reliability, efficient deployment, ease of use, and cost savings.
· Kingsoft Cloud Cloud-Native AI Suite: A service suite powered by Kingsoft Cloud Container Service that supports training and inference workloads. Built on the KCE container cluster, it provides a rich set of Kubernetes-native components tailored to the environments and capabilities required by AI workloads, including AI workload scheduling, asset acceleration, and intelligent operations and maintenance. Users can flexibly select components on demand to build an intelligent computing cluster that best fits their business needs.
· Kingsoft Cloud Container Instance (“KCI”): KCI provides a server-less container service that helps users to manage the full life-cycle of their containers in the cloud without pre-purchasing or managing the underlying servers. Virtual Node is implemented based on the open-source Kubernetes kubelet, supporting the use of KCI as Pod resources within the cluster. KCI is responsible for scheduling and managing underlying Pod container resources, while Kubernetes acts as the business orchestration layer above KCI to manage business workloads. After KCI takes over management of the underlying infrastructure for Pod containers, Kubernetes no longer needs to directly handle the creation, startup, and other operations of individual Pods, nor does it need to monitor underlying VM resource status. KCI ensures that resources required by Pods are available at any time.
· Kingsoft Cloud Container Registry (“KCR”): KCR provides exclusive container image security hosting services for enterprise-grade customers with strict data security and compliance requirements, multi-region deployments and large-scale clusters. It provides dedicated container image security hosting services, ensuring data security through segmented permission management and network access control
· Kingsoft Cloud Function (KCF): KCF provides users with a fully managed computing environment under the Serverless architecture. Users are relieved from managing server-related operations and deployments, and only need to write and upload core code, and KCF will run the code in a flexible, highly available and cost-effective manner. KCF features efficient development, cost-effectiveness, elastic scalability and simplified operations, and support application scenarios including file processing, data processing and web application development.
82
Table of Contents
Cloud Storage
We have developed different storage products for various application scenarios. Our cloud storage products provide cost-effective digitalized data storage infrastructure with high security, which can be deployed off premises or on premises upon request. Our key cloud storage products include:
· Kingsoft Cloud Standard Storage Service (“KS3”): KS3 is a scalable, multi-redundant, distributed, and cost-effective storage solution offered by Kingsoft Cloud. KS3 provides exabyte-level storage capacity, allowing each storage bucket to handle a high number of queries per second while ensuring up to 99.999999999% data reliability. It offers multiple storage types including Standard, Infrequent Access and Archive, supports multiple programming language SDKs and command-line interfaces, helping developers address challenges such as storage expansion, data security, and distributed access. Users can easily store and retrieve various data files, including images, audio, video, and text. Additionally, KS3 offers a storage solution optimized for AI data lakes, compatible with the HDFS and POSIX protocols. Leveraging all-flash storage, the ks3fs tool and KS3 accelerator, it meets the demands of high-performance scenarios including AI, big data and intensive computing workloads. Elastic Block Storage (“EBS”): EBS provides high-performance, low-latency, highly persistent block storage services. Through distributed clustering and multi-replica technology, it ensures data reliability of up to 99.999999999%. The ultra-fast ESSD cloud disk adopts a proprietary storage engine, delivering up to 1 million random IOPS, 4 GB/s bandwidth per disk, and consistently low latency, easily supporting I/O-intensive workloads. Among them, ESSD AutoPL cloud disks decouple capacity from performance, supporting customizable configurations with up to 1 GB/s throughput and 120,000 IOPS per disk. ESSD PL0/PL1/PL2 cloud disks feature shared mounting deeply optimized based on the NVMe protocol, breaking through single-instance limits to support sharing across multiple NVMe cloud server instances. With NVMe PR persistent reservation locks, they ensure strong data consistency and secure concurrent access, making them ideal for high-concurrency shared storage scenarios.
· Kingsoft Cloud File Storage (“KFS”): KFS is a scalable shared file storage service for KEC and EPC services. It supports standard file access protocols including NFS and CIFS, allowing existing applications to be mounted and used without any modifications. It is suitable for scenarios such as content management, enterprise office file sharing, and media processing. Advantages in ease of use, stability, and cost efficiency, the product offers features including recycle bin, snapshot, IP access authorization, and cloud monitoring, providing robust protection for business data security.
· Kingsoft Cloud High-Performance File Storage (“KPFS”): KPFS is a fully managed, ready-to-use high-performance distributed file storage service designed for GPU bare metal instances, KEC cloud servers, the StarFlow (“XingLiu”) platform, and container services. Leveraging high- performance RDMA networking, NVMe all-flash architecture and intelligent caching technology, it achieves end-to-end full-link performance optimization and delivers high-throughput, low-latency parallel file storage capabilities. It is ideal for high-performance scenarios such as AI training, autonomous driving, and video rendering. The service supports data mobility between KPFS and KS3, as well as recycle bin, snapshot, NFS protocol, and cloud monitoring features, along with automatic mounting on startup. With deep integration into the XingLiu platform, bare metal computing resources, and the cloud-native container ecosystem, KPFS provides a one-stop high-performance storage solution for intelligent computing workloads.
· Kingsoft Cloud Data Migration Service (“KMS”): KMS aims to assist users in migrating data from other cloud vendors or on-premises IDCs to our Object Storage Service. We provide both online and offline migration to meet various migration scenarios. Online migration involves deploying software to migrate user data to KS3 and is suitable for scenarios with small data volumes, stable network environments and sufficient bandwidth. Offline migration entails deploying hardware in the data source IDC to migrate a large number of files offline to KS3, which addresses challenges such as low transmission efficiency, long transmission times and poor security in large-scale data transfer scenarios.
83
Table of Contents
Cloud Network
Our cloud network products provide cloud-enabled or cloud-based network resources and services, offering reliable and secure network access and connections, to help users optimize resource allocation. Our key cloud network products include:
· Shared Load Balancing is a network service that automatically distributes network traffic across multiple backend servers. By configuring a virtual service address (VIP), it pools multiple backend servers in the same region into a high-performance, highly available application service pool, and distributes client requests to servers in the pool according to specified policies. Kingsoft Cloud Shared Load Balancing have features including support both public and private network service types, provide Layer 4 (TCP, UDP) and Layer 7 (HTTP, HTTPS) network services, support Elastic IP binding and unbinding to improve service flexibility and availability, support health checks to automatically isolate backend servers in abnormal status based on configurations; supports session persistence to continuously route requests from the same client to the same backend server, offer a centralized certificate management system for HTTPS to meet diverse requirements for reliable, efficient and secure data transmission.
· Dedicated Load Balancing is a traffic distribution service that routes access traffic to multiple backend servers based on policies. Compared with shared load balancing, it delivers higher performance and richer features, providing load balancing services with isolated underlying resources. Kingsoft Cloud Dedicated Load Balancing supports public network, private network and combined public-private network service types; allows on-demand enabling of Layer 4 (TCP, UDP, TCP SSL) and Layer 7 (HTTP, HTTPS, QUIC) capabilities; supports integration with WAF, which can be enabled on demand to provide application-layer security protection.
· Elastic IP (“EIP”): EIP provides independently purchasable public IP resources for user accounts, including IP addresses and bandwidth resources. Once resource bounded to EIP, user accounts can directly access the public network. Currently, Elastic IP supports binding to ECP, Bare Metal services, Shared Load Balancing, Dedicated Load Balancing, Container Instances, Secondary Network Interfaces, and High-Availability Virtual IPs. Elastic IP is a regional-level resource and can be bound to cloud resources within the same region.
· Band Width Share (“BWS”): BWS enables sharing peak bandwidth across multiple EIPs, allowing centralized bandwidth throttling based on these EIPs and flexible adjustment of bandwidth. BWS consists of a public network bandwidth and a group of EIPs, all of which can share the same bandwidth, thereby increasing flexibility in bandwidth usage and reducing costs. Shared Bandwidth supports multiple billing modes, including fixed bandwidth pricing, peak bandwidth pricing, and traffic-based pricing. Multiple shared bandwidth instances can be created for various businesses, enabling flexible bandwidth adjustment and convenient management of Elastic IP addresses.
· Virtual Private Cloud (“VPC”): It enables users to build logically isolated, self-managed dedicated networks, allowing to deploy various Kingsoft Cloud services within customized virtual networks, including ECP, bare metal services, load balancing, cloud databases and other cloud resources. In addition, users can connect VPC with their on-premises data centers through dedicated lines, IPsec VPN and other connections to build hybrid cloud solutions and achieve smooth cloud migration. As a private network isolated based on VXLAN, it ensures mutual independence among multiple tenants. Network ACLs and security groups control network access at the subnet and server levels respectively, with fine-grained control down to protocols and ports, delivering multi-dimensional and comprehensive protection to meet customers’ security requirements.Network Address Translation (“NAT”): NAT is a service that converts private IP addresses and public IP addresses within a Virtual Private Cloud (“VPC”), allowing cloud servers or cloud physical hosts without public IP addresses to access the Internet. Kingsoft Cloud NAT is suitable for scenarios requiring large bandwidth, high usage of public IPs, and multiple services for public access. If users wish to hide the public IP of hosts within the VPC to avoid exposing their network infrastructure while still accessing the public Internet, Kingsoft Cloud NAT fulfills this requirement.
· Peering: VPC Peering is a service used for cross-VPC network data synchronization, enabling network communication between two peered VPCs. It supports VPC interconnectivity in the same or across regions and accounts. By configuring routing on both ends, traffic can flow seamlessly between different VPCs. Peering Connection is built on Kingsoft Cloud’s gateway clusters, featuring high performance and high availability.
84
Table of Contents
· Cloud Enterprise Network (“CEN”): CEN aims to provide customers with a high-quality, large-scale cloud-wide area network that offers enterprise-level communication capabilities. It supports multiple scenarios, such as VPC-to-VPC connectivity in the cloud and VPC-to-on-premises data center connectivity. By creating a CEN instance, users can add network instances that require interconnection (either user-created VPCs or boundary gateways for on-premises data center access) and configure routing. Users can also define bandwidth between connected regions, quickly building a dedicated WAN in the cloud.
Cloud Databases
We have a full stack database product portfolio, including relational databases and NoSQL databases, which are used to accommodate a wide variety of data models. We provide second-level failover capability, low latency cross-cloud synchronization, multi-region disaster recovery capability, and loss less data reliability support capability for important application scenarios such as financial services, internet, and public service. Our key cloud database products include:
· Kingsoft Cloud Relational Database Service (“KRDS”): KRDS is a stable, reliable,flexible and out-of-box online relational database. Through kernel-level and hardware-level optimizations, it delivers higher performance and stability compared with self-built databases. It is equipped with multiple security protection measures and a comprehensive performance monitoring system, while providing professional database backup, recovery and optimization functions, enabling enterprises to focus on application development and business growth.
· Kingsoft Cloud Redis Cloud Database: Kingsoft Cloud Redis Cloud Database provides Online caching and key-value storage service. It supports both primary-replica and cluster architectures, and offers standard edition and self-developed cloud-native enterprise edition. In addition to basic product management features such as automatic disaster recovery switchover, instance monitoring, and online scaling, the cloud-native Enterprise Edition delivers superior performance and stability in large-scale deployment scenarios, along with more comprehensive and advanced capabilities.
· Kingsoft Cloud MongoDB Cloud Database: Kingsoft Cloud MongoDB Cloud Database is a document-oriented database that is fully compatible with the MongoDB protocol. It supports various architectures such as replica sets, sharded clusters and multiple versions. With capabilities such as high availability, backup and recovery, comprehensive monitoring, and auxiliary operations, it offers customers an integrated MongoDB fully managed service solution.
· Kingsoft Cloud Vector Database Milvus: Kingsoft Cloud Vector Database Milvus is specifically designed to handle input vector queries, capable of processing indexes with billions of vectors. It finds wide applications in AI domains such as intelligent customer service, recommendation systems, NLP services and computer vision. It serves as an external knowledge base for large models, expanding the cognitive boundaries of such models.
· Kingsoft Cloud Database Management Platform (“KDMP”): KDMP is a database management product that offers asset management for multiple types of databases and monitoring dashboards across multiple instances. It facilitates the usage and operation of databases for customers, reducing operational pressure and costs.
· Kingsoft Cloud Data Transmission Service (“KDTS”): KDTS is designed for data migration, synchronization and subscription among data sources. In addition to meeting common application scenarios such as non-stop data migration and synchronization, it also fulfills the requirements of business application scenarios such as database disaster recovery and data integration. KDTS currently supports various mainstream databases, including relational, non-relational and analytical databases.
85
Table of Contents
Big Data
We have a comprehensive stack of big data products and compatibilities. All products are empowered by providing elastic scaling and seamless access to cloud storage. We also provide an interactive query engine for users to easily organize and analyze data on the cloud, which is an important step in utilizing data lake. In response to industry-wide developments in the research on computer vision, automatic speech recognition and natural language processing, we have built the underlying technologies that underpin big data platforms. Our key big data products include:
● Kingsoft Cloud Managed Hadoop/MapReduce (“KMR”): KMR is a big data platform built on Kingsoft Cloud that provides functions for collecting, storing, processing, and presenting massive amounts of data. The KMR platform not only helps enterprises extract knowledge from big data but also supports business decision-making and data applications. Fully compatible with the open-source Hadoop/Spark community, KMR enhances the usability and stability of open-source components while offering managed operation, elastic management, and security control for big data platforms. This allows enterprises to focus on their business, improve efficiency, and reduce costs and timelines for infrastructure development.
● Kingsoft Cloud Managed Kafka: Managed Kafka is an important component of the KMR product suite and is a distributed, high-throughput, and highly scalable messaging system built on Kingsoft Cloud. The Kafka-based message queue is widely used in big data fields such as log collection, monitoring data aggregation, stream data processing, and both online and offline analytics, making it an indispensable part of the big data ecosystem.
· Kingsoft Cloud KMR Serverless Computing Engine: A fully managed serverless product designed specifically for processing large-scale data and executing complex computing tasks. It integrates three popular computing frameworks including Apache Spark, Apache Flink, and Ray, delivering an out-of-the-box, highly elastic, high-performance computing solution that eliminates the need to manage underlying servers.
· KMR Serverless StarRocks: A fully managed, high-performance analytical data warehouse featuring a decoupled storage-compute architecture. Users do not need to manage physical resources, only compute and storage. The product is fully compatible with open-source StarRocks and supports cluster creation, scaling, resizing, elastic expansion, configuration management, public network access, monitoring, and performance analysis, simplifying O&M and improving flexibility.
· Kingsoft Cloud Elasticsearch Service (KES): KES provides fully managed and performance-optimized open-source Elasticsearch, with out-of-the-box usability, elastic scaling, and a hot-cold architecture, significantly reducing operational complexity. It integrates X-Pack security and VPC isolation to ensure data security, and supports automatic snapshot backup to object storage (KS3) for high reliability. It also provides vector search capabilities to meet diverse search and analytics scenarios.
· Kingsoft Cloud Log Service (“KLog”): KLog is a comprehensive solution for managing log data. It offers a range of services including log collection, storage, processing, retrieval analysis, real-time consumption, data delivery, alerting and visualization, which enhance operational and maintenance efficiency. Users can seamlessly access the service within five minutes without concerns about resource scaling issues, enjoying stable, reliable, and intelligent log management services.
· Kingsoft Cloud Data Warehouse ClickHouse (“ClickHouse”): ClickHouse is a distributed column-oriented database designed for online analytical processing queries. It enables flexible and fast creation of clusters of various specifications in the cloud and provides comprehensive auxiliary operation and maintenance functions, effectively simplifying the workload of deployment and maintenance.
· Kingsoft Cloud Relyt (“Relyt”): Relyt is a cost-effective, native and intelligent data cloud service that is accessible to everyone. Built on the latest generation of cloud computing technologies and leveraging breakthrough data processing architectures, Relyt delivers outstanding data warehouse query capabilities, significantly enhancing cost-effectiveness, availability and user experience.
86
Table of Contents
StarFlow (“Xingliu”) Platform
· XingLiu Training & Inference Platform: The Training and Inference Platform provides cloud-native AI computing power and full-process management capabilities for developers and operators in machine learning scenarios. It consists of modules including basic resource management, computing power management tools, training and inference task management, and asset and permission management. Core features include GPU fault self-healing, task observability, and task orchestration and scheduling. It aims to provide users with a one-stop platform for training and inference task management, ensuring stable and efficient task execution and improving computing resource utilization.
· XingLiu Model API Service: The Model API Service targets large language model application developers and enterprise users, providing highly available and easily integrable model invocation and management capabilities covering the full lifecycle of model usage. The platform features flexible access control and monitoring, supports high-concurrency inference and multi-model management, and helps users efficiently access various model resources. It is designed to provide developers with a one-stop model invocation and management platform, simplifying integration, improving efficiency, and accelerating the deployment of large language model applications.
· XingLiu Agent Service: The Agent Service is a full-lifecycle development and runtime platform built to lower the barriers to Agent development, offering a fast, elastic, and highly available serverless computing and execution environment for intelligent agents. Throughout the entire development and deployment pipeline, it natively supports mainstream frameworks such as LangGraph and LangChain. Developers can easily initialize Agent projects, perform local or online debugging, package code, and deploy to the cloud with one click using the dedicated CLI tool.At the core component level, the platform deeply integrates a rich application ecosystem for Agents, including: A controlled isolation sandbox for secure code and tool execution; MCP tools and a Skill center for flexibly expanding large model capabilities; An enterprise-grade knowledge base (RAG foundation) to reduce model hallucinations; A long-term memory base enabling continuous cognition and consistent personalized interaction. In addition, it provides end-to-end full-link observability tracing and systematic intelligent quantitative evaluation mechanisms to comprehensively ensure the effectiveness, performance, and security of enterprise-grade Agents in real business scenarios.
Cloud Security
We provide users with a full range of high-quality cloud security products to effectively address cloud service abuse issues and provide users with secure, stable and reliable cloud services. Our key cloud security products include:
● Kingsoft Cloud Advanced Defense (“KAD”): KAD is a managed Distributed Denial of Service (DDoS) protection service that safeguards our users’ applications running on our cloud from attack. KAD provides T-level DDoS protection for both cloud-based and on-premises user businesses. Leveraging our KAD, users can defend against large-scale DDoS attacks in the cloud by cleansing and mitigating the attack traffic. Through advanced protection algorithms, malicious attack traffic is intercepted, while legitimate traffic is forwarded back to the source, ensuring high interception rates and safeguarding business stability and continuity.
● Kingsoft Cloud Native Advanced Defense (“KNAD”): KNAD is a product designed to provide DDoS protection capabilities for businesses deployed within Kingsoft Cloud. By binding cloud-based IPs, it can offer protection capabilities, eliminating the need for changing business IPs and tedious onboarding processes. It features real-time defense, low latency, and high reliability.
● Kingsoft Cloud Web Application Firewall (“WAF”): WAF is a firewall for web applications, ensuring security and reliability of users’ websites. Users can seamlessly deploy WAF without altering any system structure. WAF is a security product designed to help users address web attacks, business access risks, vulnerability exploitation and backdoor intrusions. With simple configuration, users can obtain web application attack protection capabilities within minutes, preventing malicious intrusion into website servers and ensuring the secure operation of customer websites and web services.
● Kingsoft Cloud Model Application Firewall (“MAF”): MAF is a security protection SaaS service tailored for foundation model training and inference scenarios. Targeting prevalent risks in model application, including model abuse, non-compliant content generation and sensitive data leakage, MAF delivers comprehensive security capabilities such as prompt injection prevention, content compliance detection, sensitive data desensitization, as well as audit and traceability, building a robust security barrier for large model training and inference services both on and off the cloud.
87
Table of Contents
Cloud Delivery
Our cloud delivery products have evolved from a simple acceleration tool for one-way static content to a complex application and streaming delivery carrier, enabling our customers to deliver an interactive and immersive user experience. Our comprehensive end-to-end cloud delivery solutions allow users to build their applications on our cloud platform and utilize additional value-added services offered by us, such as large-scale storage, streaming encode and decode, and high definition video solutions, to further enhance their business operations. Our large-scale, high-concurrency, low-latency, secure and reliable cloud delivery services help our users enhance their users’ experience.
With 5G deployment and advancement of edge computing, we continue to upgrade our cloud delivery network with more connected nodes and reiterate the advantages of our cloud delivery products. Streaming content represents a significant portion of the internet traffic, and is a major application scenario of our cloud delivery products. Streaming content captures a large share of users’ time spent as it becomes the key distribution medium for various industry verticals, such as entertainment, e-commerce, education, traveling and advertising. Leveraging the relationship we built with our clients through our cloud delivery products, we have the natural advantage to cross-sell other cloud products, such as computing, storage and database products, to explore additional monetization opportunities.
● Kingsoft Cloud Live-video Service (“KLS”): KLS is a network system based on Kingsoft Cloud’s comprehensive IaaS infrastructure. Through industry-leading video-encoding technology and powerful distribution capacities, KLS provides low-latency, high-concurrency, and stable live streaming services. KLS supports live streaming upload and download acceleration, as well as real-time transcoding, recording, watermarking, screenshots, second-level streams status management, delayed playback and many other value-added functions and applications. Meanwhile, KLS can be seamlessly integrated with the PaaS platform of Kingsoft Cloud Video Cloud, and it features fast access, multi-terminal adaptation, multi-protocol support, and easy-to-use.
● Kingsoft Cloud Media Transcoder is a distributed system for multi-media processing service. Based on the deep learning of massive multimedia data, Kingsoft Cloud Media Transcoder establishes a scientific video quality evaluation system, combined with powerful encoding/decoding technology, to provide fast, intelligent and stable media processing service.
● Kingsoft Cloud Edge Computing Network (“KECN”): KECN is a distributed edge computing network that supports edge computing scenarios such as edge bandwidth, AI inference, image rendering, gaming and IoT. We have established an end node network covering most regions and operators in China and ensuring high-speed and low-latency for customers.
● Kingsoft Cloud Delivery Network (“KCDN”): KCDN is a distributed network consisting of server clusters of edge nodes covering different regions, which distributes user content to edge nodes, effectively resolves the congestion of an internet network, and improves the response speed of users to visit the websites and the availability of the websites.
● Kingsoft Cloud Image Enhancement (“KIE”): KIE is an intelligent image enhancement product, which is able to recover and enhance image details by deep learning algorithms. It can also enhance resolution and output high-quality images.
● Kingsoft Cloud Smart High Definition (“KSHD”): KSHD integrates various computer vision and video coding technologies to substantially improve the quality of experience. It uses deep-learning-based denoise and enhance algorithms to reduce compression artifacts as well as enhance details. Meanwhile, KSHD is capable of analyzing video by way of classification and quality assessment, so as to improve the coding efficiency of video code.
88
Table of Contents
Galaxy Stack
Our proprietary Galaxy Stack essentially allows customers to deploy a public cloud architecture within their internal IT infrastructure, so that they can have the same experience as public cloud services within their IT premise, while fulfilling regulatory compliance and retaining control. Galaxy Stack employs a distributed architecture to create an open, unified and reliable cloud environment for enterprises and organizations. As a result of our continuous upgrading and optimization efforts, Galaxy Stack features comprehensive IaaS, PaaS, security, maintenance products and services, as well as the self-developed training and inference platform and model services to provide more professional, scalable and mature one-stop cloud solutions.
The key value we bring includes:
· Scalability at large scale: Galaxy Stack enables large-scale physical node deployment, massive tenant management and customer service capabilities, which strongly support customers’ massive business operations. Customers can easily adjust the physical node deployment based on their real-time demands.
· One-Stop AI Platform Capabilities: Providing full lifecycle management covering model development, training, inference and resource monitoring, with seamless integration of underlying resource scheduling, computing power optimization, task orchestration and permission control across the entire chain.
· Security: Privatized deployment meets the requirements of enterprises and organizations for high-grade information security protection, data security and business continuity.
· Autonomous control: Galaxy Stack supports customers’ autonomous control operation and maintenance.
We have been dedicated to upgrading our Galaxy Stack product, including introducing new features in training and inference platform, inference framework, and model serving of the AI platform, we continuously enhance product capabilities to deliver high-quality intelligent computing services in terms of performance, cost-effectiveness and stability, to meet customers’ evolving needs.
Industry-Specific Solutions
We have designed various industry-specific solutions that can unleash the full potential of our infrastructure resources and add value to our customers. Leveraging our profound industry insights, we have strategically expanded our footprints into selected verticals as an early mover and have established a leading market position through relentless execution. As we continuously serve vertical leaders, our products and solutions continue to iterate and pivot based on customers’ feedback. By partnering with vertical leaders, we have accumulated proprietary industry know-how and formed in-depth view of each selected vertical, which enables us to stay forefront of industry-specific cloud solutions. We have designed industry- specific solutions covering a wide spectrum of industry verticals, including AIGC, pan-Internet, video, public service, healthcare, intelligent mobility and financial service, among others.
AIGC Solutions
We offer a range of products, including bare metal computing servers, computing cloud servers, KS3 and AI platforms, to meet the strong computational and storage needs of clients in AI industry for model training and inference. Leveraging abundant IDC resources and hybrid cloud networking experience, we design high-availability and cost-effective underlying architecture solutions for the application deployment of our clients, effectively reducing operational costs and improving business productivity.
To address the entire AIGC development process, including data acquisition, data preprocessing, model training and model inference, we provide different delivery forms of computing, including computing cloud instances and bare metal computing servers. Clients can utilize elastic computing cloud instances for rapid model validation and flexible online scaling of inference services. For large-scale model training, we provide hundreds of bare metal computing servers along with high-performance IB or RoCE networks, combined with all-flash high-performance object storage and file storage, to provide clients with top-notch computational environments.
Furthermore, through Spark or MapReduce distributed computing frameworks, efficient data preprocessing services can be completed quickly and efficiently. Leveraging elastic resources in the cloud reduces fixed asset expenses during the preprocessing process while ensuring speed and efficiency.
89
Table of Contents
The key value we bring includes:
● Delivery Capability: We provide AIGC delivery capabilities at different levels, covering underlying IaaS resources, middleware training frameworks, and application-level model and industry application delivery capabilities. This meets the diverse needs of customers at various levels, including data acquisition, cleansing, training, inference, and industry applications.
● Trusted Collaboration Zone: The AIGC industry chain typically involves collaboration among different vendors, including data providers, model training vendors, and end-users. Therefore, controlled interoperability of data and final models among these stakeholders is essential. We provide Trusted Collaboration Zone services to establish a trusted environment for collaboration among different vendors.
● Ready-to-Use: Users do not need to procure and build the entire AIGC infrastructure environment from scratch. They can simply select the corresponding hardware configuration from our console based on different scenarios and computational requirements, and the accompanying high-performance networking and storage are ready to use. The service supports pay-as-you-go billing, and resources can be quickly released after tasks are completed.
● Elastic Scalability: AIGC exhibits significant variations in resource requirements across different business cycles, manifested in two dimensions. Firstly, different stages of AIGC have distinct resource demands. For example, the data cleansing stage typically requires massive computing resources, while the application of the final model requires a large number of computing resources. Secondly, there may be hotspots in inference applications, requiring the ability to supply a large number of resources in a short time. Our Elastic Scaling service, combined with backend pooled cloud servers, can achieve elastic resource scaling in minutes.
Dedicated Cloud Solutions
Dedicated Cloud is a cloud computing service model based on dedicated physical devices, providing customers with a fully physically isolated block storage cluster to achieve end-to-end exclusive deployment of computing and storage resources. This solution delivers hardware resources exclusively to a single customer, ensuring zero resource sharing, while also incorporating the elastic scalability of the cloud to meet the enterprise’s core requirements for data sovereignty, high performance, and strong security compliance.
Dedicated Cloud is particularly suited for core business systems in industries such as finance, government, healthcare, and high- end manufacturing. It can support business scenarios with high demands for resource exclusivity and stability, such as ERP, core databases, and big data analysis platforms, providing a cloud infrastructure that combines the security of private clouds with the agility of public clouds.
By deeply integrating the mature high-availability architecture of public cloud with the physical isolation characteristics of Dedicated Cloud, while also maintaining “controllability” and “cloud capability,” this solution achieves the best of both worlds.
The core advantages include:
● Physical-Level Security Isolation
o Physical Isolation: dedicated cloud provides independent storage resource pools through physical isolation, ensuring that user services and data are completely segregated from other users.
o Compliance Support: Meets stringent requirements for data security and compliance, ensuring that businesses in sectors such as finance and healthcare comply with relevant regulatory standards.
90
Table of Contents
● Flexible Resource Autonomy and Control
o Self-Management: Users have full management rights over storage resources, allowing them to flexibly allocate, adjust, and optimize storage capacity and performance based on their needs, without relying on cloud service providers.
o Customizable Configuration: Supports customization of computing (e.g., number of cores, memory) and storage performance parameters (e.g., IOPS, throughput) based on business requirements, catering to personalized needs in different application scenarios.
o Granular Access Control: Provides fine-grained access control, enabling users to configure access policies based on business needs, ensuring that only authorized personnel can access sensitive data.
● Full Lifecycle Operational Support
o While enjoying exclusive physical resources, users can still leverage capabilities such as multi-active disaster recovery and cross-cluster backup, consistent with public cloud, to ensure critical business systems meet rigorous reliability and availability requirements.
o Seamless Integration with Public Cloud Ecosystem: Supports direct integration with global load balancing, cloud monitoring, and automation operations tools from public cloud, ensuring the operational experience and API compatibility are identical across dedicated cloud and public cloud, reducing hybrid cloud management complexity.
The scenario value includes:
· Zero Transformation for Business Systems: Traditional systems can be migrated to dedicated cloud without reengineering, gaining the elasticity of cloud computing
● Acceleration for Data-Intensive Applications: Provides stable, high-performance computing power for AI training, real-time risk control, genetic sequencing, and other scenarios.
● Compliance-Driven Industries: Meets strict regulatory requirements such as “same-city dual-active + offsite disaster recovery” for the financial sector and “one department, one cluster” for government cloud.
Video Cloud Solutions
We started to offer video cloud solutions in 2016, prior to the explosive growth of the video industry in China. Our full stack video cloud solutions offer various state-of-the-art deep learning algorithms, including cloud trans-coding, image enhancement, smart high definition, dark image enhancement. Our holistic intelligent video cloud solutions serve both on-demand video and live streaming companies, offering a high-capacity and elastic cloud delivery network built on our industry-leading containerized edge computing platform. To meet the large-scale and high-quality cloud delivery requirements of these companies, our video cloud solutions combine core technologies such as intelligent video processing algorithms and multi-link optimization to provide enhanced cloud delivery services beyond traditional content delivery services. For on-demand videos, we offer video upload, distributed encoding, media resource management and on-demand delivery. For live streaming, we offer delivery acceleration, real-time encoding, live recording and storage. Our video cloud solutions can be accessed through a management system or API/SDK.
The key value we bring includes:
● High Speed: Our video cloud solutions provide a quick and uninterrupted video streaming, archiving experience and lossless transmission.
● Stability: Our video cloud solutions offer high stability and ensure performance. The distributed network eliminates incidents and disruptions, which can effectively lower packet loss rate.
91
Table of Contents
● Security: Our video cloud solutions are able to maximize data security by configuring authentication settings for content.
● High Definition: Our video cloud solutions provide optimized encoding and decoding solutions that allow 4K-8K ultra high-definition video transmission through the internet.
● Elastic Expansion: Our video cloud solutions provide deep integration with public clouds, offering agility and flexibility to allocate resources on demand and respond promptly to business changes.
● Cost Reduction: Our video cloud solutions offer fine management of cloud resources and optimization of IDC costs, significantly reducing costs.
Public Service Cloud Solution
Our public service cloud solutions are based on the public cloud architecture and can be easily and quickly deployed. These cloud solutions help public service organizations enhance productivity and efficiency.
The key value we bring includes:
● Digitalization: Public service organizations are able to connect data across multiple departments, improve work efficiency, enhance security, and transform data resources into data assets, which ultimately realize digital transformation.
● Reliability: The cloud platform adopts high-availability technology and security protection system, which can guarantee the stable and uninterrupted operation of the platform.
● Comprehensiveness: Based on the public cloud technologies, we can provide a series of services from the construction, operation and management of underlying cloud data center, big data management, big data analytics, etc., which meets the public service organizations’ requirements for critical aspects of cloud platform product functions.
● Intelligence: Based on the public service cloud, we provide AI-powered services for specific industries and fields, helping organizations enhance production efficiency and achieve higher levels of business intelligence.
Digital Healthcare Solutions and Services
Our digital healthcare solutions and services provide high-performance, reliable, secure resources and technologies, and a full portfolio of applications and services for the healthcare industry. We provide cloud services covering hospital operations, medical supervision, medical insurance payment, medical treatment and eldercare relying on our top-level cloud resources, abundant cloud products and excellent cloud service. It features big data analysis service for administrators, health management service for residents, cloud infrastructure for large and medium medical institutions and cloud application service for small and medium medical institutions.
Our digital healthcare solutions and services feature platformization, integration and digital intelligence, integrating five major business segments, including regional health cloud, medical imaging cloud, regional core business cloud, medical community platform and intelligent hospitals. We have successfully deployed flagship projects for leading institutions.
● Regional Healthcare Cloud: Targeting regional medical and healthcare businesses at the provincial and municipal levels, employing cloud computing, big data, artificial intelligence, middleware architecture, blockchain, and other emerging technologies to empower both technical and business aspects of regional medical and healthcare applications. The initiative aims to construct a cloud-based, data- aggregated, comprehensively governed, and business-interconnected medical and healthcare big data center. It aligns with the General Medical Information System (GMIS) to enable the integration and coordination across healthcare infrastructures.
92
Table of Contents
The key value we bring includes (i) achieving near-real-time data aggregation into the data lake, establishing a comprehensive healthcare big data center covering the entire region; (ii) reconstructing regional business applications with a comprehensive middleware architecture, standardizing and sharing applications from dimensions such as architectural specifications, technical standards, data standards, and business capability sharing, thereby achieving intensive and efficient business application management. (ⅲ) Enhance the comprehensive decision-making and analytical capabilities of healthcare administration departments through data and AI-powered intelligent applications.
● Medical Imaging Cloud: Targeting regional healthcare administrative departments, we adopt an integrated “construction, management, and operation” model to build a regional imaging cloud that unifies platforms, innovates services, and aggregates ecosystems. Through the regional imaging cloud, regional medical resources can be effectively integrated to achieve regional imaging synergy and mutual recognition of results, thereby promoting hierarchical diagnosis and treatment, facilitating the sharing of medical imaging data, and deeply unlocking the core value of medical imaging data.
● Regional Core Business Cloud: We propose the concept of coordinated high-quality development of regions and medical institutions for regional public hospitals, constructing a SaaS-based regional medical core business platform. This platform employs a multi-tenant architecture to enable multiple hospitals to share the platform without affecting each other. Through regional coordination of data platforms, it achieves the unity of hospital data centers and regional data centers, ensuring that all medical institutions in the region obtain high-quality, digital-intelligent integrated business systems, thereby facilitating hospitals and regions to jointly achieve various high-level certifications.
● Medical Community Platform: For closely-knit county-level medical community businesses, leveraging emerging technologies such as cloud, big data, IoT, and AI, constructing a medical community information platform with a middleware architecture, providing integrated solutions for comprehensive data management and decision-making, intelligent primary medical services, collaborative services for regional medical institutions, smart medical services, convenient and beneficial health services, unified management of personnel, finance, and materials, as well as operational supervision.
● Intelligent Hospitals: Targeting large hospitals and medical research institutions, we provide end-to-end digital and intelligent transformation solutions ranging from underlying infrastructure to upper-level core applications. Relying on our profound industry understanding and robust cloud, data, and AI technologies, we comprehensively reshape hospital business workflows, focusing on building three core capabilities.
o Cloud-based Architecture Transformation: Digitally redesigning hospital information systems with a focus on architecture reconstruction. We comprehensively drive the evolution of hospital business systems towards microservices and containerization, achieving the decoupling and agile iteration of underlying systems. This significantly enhances the systems’ high-concurrency processing capabilities and business continuity, laying an extremely stable and secure cloud architecture foundation for the hospital’s digital-intelligent transformation.
o Integrated Data Center Solution: Expanding data assets and capabilities via middle platform architecture, artificial intelligence and lake-house technologies to build a hospital-wide, multi-modal data asset management platform that breaks down information silos across departments. It enables the global aggregation and governance of core assets such as patient diagnosis and treatment records, pathology, imaging, biological samples, and operational data. This comprehensively supports the transformation of the hospital’s data architecture, allowing data to truly unleash its value in clinical research and management.
o AI Solutions for Hospitals: Based on a one-stop Model-as-a-Service (MaaS) platform, we provide end-to-end capabilities covering AI-native infrastructure, model management, data platforms, and application development to comprehensively optimize diagnosis, treatment, and operational efficiency:
◾ AI-as-a-Service Model Production: Based on a dedicated model production platform (KAX), we enable full-lifecycle management of large models, including incremental training, fine-tuning, prompt engineering, and automated deployment. It is fully compatible with diverse foundational models and open-source large model ecosystems.
93
Table of Contents
◾ Smart Office and Clinical Assistants: Deeply integrating core AI assistants like WPS AI to provide robust medical document understanding and generation capabilities. This vastly improves the efficiency of intelligent electronic medical record drafting, medical record summarization, clinical logical reasoning, and automated documentation processes.
◾ Smart Operation Management Assistants: Building an “Intelligent Data Query Agent” based on healthcare business ontology models to break the limitations of traditional, rigid dashboards. Hospital administrators can use natural language interactions to instantly and accurately retrieve and analyze various complex operational metrics, such as human resources, finances, materials, and performance. Achieving a “what you ask is what you get” experience, it deeply empowers refined operation management and digital-intelligent scientific decision-making in hospitals.
Financial Service Cloud Solutions
We have pioneered the private deployment of public cloud technologies, which could effectively address the pain points faced by financial institutions amid the regulatory requirements and digital transformation, and allow them to unleash the value of data assets. For example, our Data Lakehouse platform has been successfully deployed for a large state-owned bank in China. Furthermore, we, through Camelot, offer comprehensive and digitalized solutions such as teller or branch systems, anti-money laundering and fraud prevention software services to the financial services industry. The key value we bring includes:
● Digital transformation: Our customized financial service architecture solutions, by providing high-performance cloud computing service at lower costs, enable financial institutions to achieve digital transformation and migrate to cloud.
● Cloud native benefits: Our financial service cloud native solutions enable financial institutions to enjoy various benefits brought by cloud technologies, including high security, reliability, availability and flexibility.
● Business innovation: Our intelligent financial service solutions equip financial institutions with big data analytics capabilities, enabling them to easily and efficiently realize business innovations.
Other Solutions
Our cloud solutions also cover various other industries, such as game, e-commerce, office automation and mobile internet in general, among others.
Our Infrastructure and Technologies
We are dedicated to providing customers with secure and compliant cloud services and our industry-leading cloud infrastructure and technologies have been the key to our success.
Infrastructure
Our distributed infrastructure is the foundation of our technology. As of December 31, 2025, we owned two data centers and approximately 101,500 servers primarily throughout China, and achieved exabyte-level storage capacity. We have been investing significantly in our infrastructure to upgrade our computing power and storage capabilities, in order to deliver higher-quality cloud service and enhance the economies of scale. We purchase and lease servers, network equipment, network resources and data centers from industry-leading suppliers to ensure the reliability and availability of our network infrastructure. Our suppliers primarily include IDC operators, telecommunication operators and server providers in China.
94
Table of Contents
Cloud Technologies
We create and apply cutting-edge technologies to drive our development of products and solutions. Our core technologies include:
Cloud Native
We provide various computing delivery models, including container clusters, serverless container instances, and cloud functions. Our solutions support managed image repositories, Prometheus monitoring systems, service meshes, and other key ecosystem components, offering customers scalable and flexible cloud-native infrastructure.
Virtualization
We have built a complete virtualization technology stack. Technologies like x86/ARM CPU virtualization, memory virtualization, high-performance storage and network virtualization, GPU (graphics processing unit) virtualization, with critical features such as smooth live migration and live patching, are all well supported and applied to our cloud products. Additionally, the introduction of new hardware, such as smart NICs offloads storage and network I/O, further reduces latency and provides excellent support and user experience for our cloud products.
Software Defined Network
Our virtualized network architecture, designed on the basis of disaster recovery multi-region construction, supports multi-tenant networks. With petabit-per-second-scale distributed east-west forwarding capabilities and terabit-per-second-scale north-south traffic capabilities, the cloud network provides high-performance interconnect services for computing, storage and various PaaS services. By combining software and hardware technologies and introducing new hardware such as programmable switches and smart network interface cards (NICs), we continuously improve the performance of the underlying network. Additionally, based on network function virtualization and leveraging industry ecosystems, we provide users with richer product functionalities and interconnection experiences.
Distributed Storage
We have developed different storage technologies for various application scenarios, including object storage, table storage, elastic block storage, and file storage, providing high-performance storage services with reliability, scalability and availability.
Cloud Delivery
We have developed a comprehensive set of cloud delivery systems, including caching system, OTCP (optimized transmission control protocol) stack, user datagram protocol-based transport stack, traffic scheduling system, high-performance domain name system, near-real-time performance analysis system and IPV 4 (internet protocol version 4) and IPV 6 (internet protocol version 6) dual-stack network system.
Data Lake and Data Analytics
Our data lake technology enables the storage, management, and analysis of massive volumes of structured and unstructured data, offering customers a simple, cost-effective, and maintenance-free big data computing platform. Such technology allows businesses to gain insights from their data, facilitating more informed decision-making.
Research and Development
Our vision and focus on innovation have fueled our growth and enabled us to deliver our products and services. We allocate a substantial portion of our operating expenses to research and development, including upgrading our infrastructure, improving our cloud technology and developing new products and solutions. We incurred RMB784.8 million, RMB846.0 million and RMB810.3 million (US$115.9 million) of research and development expenses in 2023, 2024 and 2025, respectively.
95
Table of Contents
Our leadership in technology is built by our highly innovative and dedicated research and development staff. We focus on building and maintaining a large pool of talented researchers to drive our research and development efforts. We provide rigorous training to new recruits to familiarize them with our platform and thereby closely integrate them into our research and development staff. Since 2023, we have been building our Beijing-Wuhan dual Research and Development Center. We had a team of approximately 1,120 engineers, researchers, programmers and computer and data scientists as of December 31, 2025. We encourage different points of view to lead us to find inspiration and improve our products and solutions.
The development of our cloud products and solutions is underpinned by our strong R&D capabilities. Our continuous investments in research and development activities result in a wealth of intellectual properties. As of the date of this annual report, we have registered 1,528 patents, 716 trademarks, 910 copyrights, and 135 domain names in China and overseas.
In addition, we aim to increase our research and development efforts to strengthen our technology capabilities and continue to invest in cutting-edge technologies such as AI, edge computing, container and data lake. We also aim to further expand our talent pool of top-notch engineering specialists as well as industry vertical experts.
Data Privacy and Security
Data security and privacy are our highest priority. To this end, we constantly enhance our data system resilience, protect user privacy, and show transparency on how we manage it. We aim to deliver high-quality cloud services with careful data and information protection, and we are in relentless pursuit of security-driven innovations to provide effective solutions. We value transparency in our data management practices and have issued the Privacy Policy, the Kingsoft Cloud Security White Paper, and the Cookies Policy on our official website to clarify the way we collect, store, use, share and delete personal information in relation to Kingsoft Cloud products, services, websites, and other application scenarios. We have designed strict data protection policies to ensure that the collection, consolidation, use, storage, transmission and dissemination of such data are in compliance with applicable laws and with prevalent industry practice in all material respects. We also established a Security and Privacy Committee, comprised of members from various departments, including data security, privacy compliance, internal control and audit, and supervision, to ensure compliance with applicable laws and regulations in all material respects and to ensure that we meet the expectations of our customers.
We have established a robust information system in compliance with applicable data security requirements in all material respects. Our information system applies safeguards, including double-firewalls, antivirus walls and web application firewalls. We encrypt data to enhance data security. Our database can only be accessed through computers designated for authorized use. Only authorized staff can access these computers for designated purposes. We also have clear and strict authorization and authentication procedures and policies in place. Our employees only have access to data which is directly relevant and necessary for their job responsibilities and for limited purposes and are required to verify authorization upon every access attempt.
We regularly assess the effectiveness of our information system and data privacy and security policies. We closely monitor regulatory developments to ensure compliance. For example, in 2021, we conducted a full identification and review of relevant regulations and made amendments to our current data security documents based on the most recent released Data Security Law of the People’s Republic of China after looking into every detailed item within, so as to keep our data security management abreast with the latest regulations and policies. We also actively participate in legislative feedback activities, such as the “Corporate Seminar of Standard Contract Provisions on Personal Information Exportation” to provide our insights and keep us abreast with the most recent regulatory requirements. To promote awareness of data privacy and security, we regularly hold and participate in data security and privacy protection conferences, industry insight sharing and regulatory communication meetings.
We have completed various information security, privacy and compliance certifications/validations, proving the security and reliability of our data protection technologies. For example, we have obtained ISO 9001 for Quality Management System, ISO 20000-1 for Service Management System, ISO 27001 for Information Security Management, ISO 22301 for Business Continuity Management Systems, ISO 27018 for Protection of Personally Identifiable Information for Public Cloud and ISO 27017 for Cloud Security Management System. Our in-house legal and data protection team has also been awarded as Winner in cloud services, and Highly-recommended in data protection and privacy in the 2021 In-house Counsel Awards by China Business Law Journal.
As of the date of this annual report, we have not received any claim from any third party against us on the ground of infringement of such party’s right to data protection as provided by applicable PRC laws and regulations or any applicable laws and regulations in other jurisdictions, and we have not been subject to any government investigation, enquiry, action or penalty in such respects, or experienced any material data loss or breach incidents.
96
Table of Contents
Sales and Marketing
To promote our cloud products and solutions, we mainly directly reach out to our customers and in certain cases we cooperate with third-party agents. Direct sales supported by our experienced industry-focused team is our primary sales approach. To promote our cloud products and solutions, particularly when we enter into a new vertical, we intend to cooperate with industry leaders to complete lighthouse projects to demonstrate our technological capabilities and the advantages of our cloud products and solutions. We then leverage such lighthouse projects to market our products and solutions for other customers in the vertical. We seek to generate recurring revenues through after-sale services and cross-sell new solutions after we gain insights into customer needs.
We have established a professional and industry-focused in-house sales team. Our employees have deep knowledge of the industries and customers that they are responsible for. Our in-house sales team works closely with our engineering team to ensure that they can propose and integrate the most suitable solutions to address the pain points faced by participants in the relevant industry verticals.
On the other hand, our in-house sales department works closely with the sales partners and leverages their understanding of end user demands, thereby developing tailored marketing strategies.
To encourage and incentivize our in-house sales team, we have designed a compensation structure that includes both fixed and performance-based components. We set specific performance targets for each team member. We evaluate such employee’s performance every year and pay out performance-based compensation accordingly.
In addition, we have a marketing team responsible for increasing the awareness of our brand, promoting our new and existing products and services, maintaining our relationships with business partners and managing public relations.
Intellectual Property
We develop and protect our intellectual property portfolio by registering our patents, trademarks, copyrights and domain names. We have also adopted a comprehensive set of internal rules for intellectual property management. These guidelines set the obligations of our employees and create a reporting mechanism in connection with our intellectual property protection. We have entered into standard employee agreements and confidentiality and non-compete agreements with our full-time R&D staffs, which provide that the intellectual property created by them in connection with their employment with us is our intellectual property.
As of the date of this annual report, we have registered 1,528 patents, 716 trademarks, 910 copyrights, and 135 domain names in China and overseas. We have obtained the license from Kingsoft to use its “金山云” and “Kingsoft Cloud” trademarks. We have also obtained the license from Kingsoft Group to use some of its registered patents during their terms of registration. We intend to vigorously protect our technology and proprietary rights, but there can be no assurance that our efforts will be successful. Even if our efforts are successful, we may incur significant costs in defending our rights. See “Item 3. Key Information—3.D. Risk Factors—Risks Relating to Our Business and Industry—We could incur substantial costs in protecting or defending our intellectual property rights, and any failure to protect our intellectual property could adversely affect our business, results of operations and financial condition.”
Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy or otherwise obtain and use our technology. Monitoring unauthorized use of our technology is difficult and costly, and we cannot be certain that the steps we have taken will prevent misappropriation of our technology. From time to time, we may have to resort to litigation to enforce our intellectual property rights, which could result in substantial costs and diversion of our resources. In addition, third parties may initiate litigation against us alleging infringement of their proprietary rights or declaring their non-infringement of our intellectual property rights. In the event of a successful claim of infringement and our failure or inability to develop non-infringing technology or license the infringed or similar technology on a timely basis, our business could be harmed. Even if we are able to license the infringed or similar technology, license fees could be substantial and may adversely affect our results of operations.
As of the date of this annual report, we did not have any material disputes or any other pending legal proceedings of intellectual property rights with third parties.
97
Table of Contents
Insurance
Our employee-related insurance consists of pension insurance, maternity insurance, unemployment insurance, work-related injury insurance and medical insurance, as required by PRC laws and regulations. We also purchase supplemental commercial medical insurance for our employees.
In line with general market practice, we do not maintain any business interruption insurance or product liability insurance, which are not mandatory under PRC laws. We do not maintain key-man life insurance, insurance policies covering damages to our network infrastructures or information technology systems. We have property insurance policies covering some of our facilities.
Our Environmental, Social and Governance (ESG) Efforts
We believe that strong ESG management is essential to the sustainability of our business. In addition to developing advanced cloud technologies, we aim to build and deliver more enabling products and services to all stakeholders.
In April 2026, we published our ESG report for 2025. The ESG report mainly includes topics of privacy and data security, customer service, technology innovation, talent attraction, development and training, business ethics and anti-corruption, and intellectual rights protection and others.
Corporate Governance
Kingsoft Cloud strictly complies with laws, regulations, and the code of business ethics, and continuously refine its governance and risk control compliance systems. The Company has formulated the “CLOUD” sustainable development strategy - Corporate Governance, Labor Cultivating, Operational Excellence, Unified Eco-Creation, and Digital Innovation, and actively responds to the expectations of stakeholders. Adhering to the laws and regulations of the jurisdictions where it operates, the Company upholds its commitment to integrity and ethical principles, working with partners to foster a fair, trustworthy, and transparent business ecosystem.
98
Table of Contents
ESG-related Risks and Opportunities
By referencing Sustainable Development Goals (SDGs), exchange requirements, investor concerns, domestic and international policies, and aligning with our corporate strategy, we have identified 18 key ESG issues. Through systematic research and analysis, we gauged internal and external stakeholders’ levels of concern for each ESG issue. Using dual dimensions of “materiality to Kingsoft Cloud” and “materiality to stakeholders”, we prioritized these key ESG issues. This year’s assessment yielded 10 highly material issues and 8 generally material issues, as shown in our materiality matrix as follows:
Labor Cultivating
We respects and safeguards our employees’ legitimate rights and interests, fosters a diverse, inclusive, healthy, and safe workplace, maintains open communication channels, and demonstrates its commitment to a human-centric corporate culture. We establish a fair, transparent, and competitive compensation and benefits system, and continuously optimize career advancement and talent development mechanisms to enable mutual growth for both employees and the Company.
Operational Excellence
We are committed to upholding the core value of “customer first, and differentiation through excellence in technology and innovation”, continuously enhancing the quality of our products and services. We create a secure, stable and reliable cloud service system, comprehensively empowering customers with efficient operations. Meanwhile, we enhance the supplier lifecycle management mechanism, practice responsible procurement principles, and drive sustainable business growth.
Unified Eco-Creation
We actively responds to the “Dual Carbon” goals, focusing on low-carbon transformation and climate change adaptation by deeply integrating green principles into the operations of data centers and daily office operations. At the same time, leveraging its technological strengths, the Company deepens its social responsibility practices, empowering critical sectors such as healthcare and public services with advanced technology, and collaborating with stakeholders to jointly build sustainable social well-being.
99
Table of Contents
Digital Innovation
We harnesses digital innovation as its core engine, building a tiered technical talent pipeline, strengthening the foundation of its technological culture, and advancing the upgrading and application deployment of the Starflow Platform. We optimize information security and privacy protection management system to enhance risk prevention and control capabilities. Furthermore, we establish a full-process intellectual property protection mechanism, fully respect innovation achievements, and continuously stimulate the intrinsic vitality of technological innovation.
Licenses and Permits
The following table sets forth the details of the material licenses and permits necessary for the operation of our business in China.
Entity Holding the License/
License/Permit Permit Grant Date Expiration Date
VAT License Kingsoft Cloud Network July 22, 2020 March 5, 2029
VAT License Kingsoft Cloud Network February 24, 2021 March 27, 2028
VAT License Beijing Jinxun Ruibo September 30, 2021 June 24, 2027
VAT License Beijing Jinxun Ruibo February 18, 2022 February 18, 2027
VAT License Kingsoft Cloud Information January 17, 2019 December 15, 2028
VAT License Kingsoft Cloud Information September 30, 2021 September 30, 2026
VAT License Kingsoft Cloud Network November 28, 2017 October 9, 2027
VAT License Nanjing Qianyi April 9, 2018 December 30, 2027
VAT License Nanjing Qianyi April 3, 2018 September 27, 2027
VAT License Wuhan Kingsoft Cloud July 26, 2024 July 26, 2029(1)
VAT License Shanghai Jinxun Ruibo January 24, 2022 January 24, 2027
VAT License Kingsoft Cloud Shenzhen December 22, 2025 October 22, 2030
VAT License QY Data January 29, 2026 May 30, 2030
As of the date of this annual report, we had obtained all material licenses, permits, approvals and certificates necessary to conduct our business operations from the relevant government authorities in the PRC, and such licenses, permits, approvals and certificates remained in full effect. These include the VAT Licenses for internet data center services, internet access services, domestic internet protocol virtual private network services, content delivery network services and information services. For the licenses or permits that are going to expire, we are in the process of renewing them.
100
Table of Contents
Regulation
Regulation Related to Foreign Investment
The establishment, operation and management of companies in China are mainly governed by the PRC Company Law, as most amended in December 2023 and taking into effect in July 2024, which applies to both PRC domestic companies and foreign-invested companies. On March 15, 2019, the National People’s Congress approved the Foreign Investment Law, and on December 26, 2019, the State Council promulgated the Implementing Rules of the PRC Foreign Investment Law, or the Implementing Rules, to further clarify and elaborate the relevant provisions of the Foreign Investment Law. The Foreign Investment Law and the Implementing Rules both took effect on January 1, 2020 and replaced three major previous laws on foreign investments in China, namely, the Sino-foreign Equity Joint Venture Law, the Sino-foreign Cooperative Joint Venture Law and the Wholly Foreign-owned Enterprise Law, together with their respective implementing rules. Pursuant to the Foreign Investment Law, “foreign investments” refer to investment activities conducted by foreign investors (including foreign natural persons, foreign enterprises or other foreign organizations) directly or indirectly in the PRC, which include any of the following circumstances: (i) foreign investors setting up foreign-invested enterprises in the PRC solely or jointly with other investors, (ii) foreign investors obtaining shares, equity interests, property portions or other similar rights and interests of enterprises within the PRC, (iii) foreign investors investing in new projects in the PRC solely or jointly with other investors and (iv) investment in other methods as specified in laws or administrative regulations, or as stipulated by the State Council. The Implementing Rules introduce a see-through principle and further provide that foreign-invested enterprises that invest in the PRC shall also be governed by the Foreign Investment Law and the Implementing Rules.
The Foreign Investment Law and the Implementing Rules provide that a system of pre-entry national treatment and negative list shall be applied for the administration of foreign investment, where “pre-entry national treatment” means that the treatment given to foreign investors and their investments at market access stage is no less favorable than that given to domestic investors and their investments, and “negative list” means the special administrative measures for foreign investment’s access to specific fields or industries, which will be proposed by the competent investment department of the State Council in conjunction with the competent commerce department of the State Council and other relevant departments, and be reported to the State Council for promulgation, or be promulgated by the competent investment department or competent commerce department of the State Council after being reported to the State Council for approval. Foreign investment beyond the negative list will be granted national treatment. Foreign investors shall not invest in the prohibited fields as specified in the negative list, and foreign investors who invest in the restricted fields shall comply with the special requirements on the shareholding, senior management personnel, etc. In the meantime, relevant competent government departments will formulate a catalogue of industries for which foreign investments are encouraged according to the needs for national economic and social development, to list the specific industries, fields and regions in which foreign investors are encouraged and guided to invest. The current industry entry clearance requirements governing investment activities in the PRC by foreign investors are set out in two categories, namely the Special Administrative Measures (Negative List) for the Access of Foreign Investment (2024 version), or the 2024 Negative List, as promulgated by the NDRC and the Ministry of Commerce and taking effect on November 1, 2024, and the Encouraged Industry Catalogue for Foreign Investment (2025 version), as promulgated by the NDRC and the Ministry of Commerce and taking effect on February 1, 2026. Industries not listed in these two categories are generally deemed “permitted” for foreign investment unless specifically restricted by other PRC laws. Industries such as value-added telecommunication business, which we are engaged in, are generally not open up or restricted to foreign investment, and we conduct business operations that are restricted to foreign investment through our variable interest entities.
101
Table of Contents
According to the Implementing Rules, the registration of foreign-invested enterprises shall be handled by the State Administration for Market Regulation, or the SAMR, or its authorized local counterparts. Where a foreign investor invests in an industry or field subject to licensing in accordance with laws, the relevant competent government department responsible for granting such license shall review the license application of the foreign investor in accordance with the same conditions and procedures applicable to PRC domestic investors unless it is stipulated otherwise by the laws and administrative regulations, and the competent government department shall not impose discriminatory requirements on the foreign investor in terms of licensing conditions, application materials, reviewing steps and deadlines, etc. However, the relevant competent government departments shall not grant the license or permit enterprise registration if the foreign investor intends to invest in the industries or fields as specified in the negative list without satisfying the relevant requirements. In the event that a foreign investor invests in a prohibited field or industry as specified in the negative list, the relevant competent government department shall order the foreign investor to stop the investment activities, dispose of the shares or assets or take other necessary measures within a specified time limit, and restore to the status prior to the occurrence of the aforesaid investment, and the illegal gains, if any, shall be confiscated. If the investment activities of a foreign investor violate the special administration measures for access restrictions on foreign investments as stipulated in the negative list, the relevant competent government department shall order the investor to make corrections within the specified time limit and take necessary measures to meet the relevant requirements. If the foreign investor fails to make corrections within the specified time limit, the aforesaid provisions regarding the circumstance that a foreign investor invests in the prohibited field or industry shall apply.
Pursuant to the Foreign Investment Law and the Implementing Rules, and the Information Reporting Measures for Foreign Investment jointly promulgated by the Ministry of Commerce and the SAMR, which took effect on January 1, 2020, a foreign investment information reporting system shall be established and foreign investors or foreign-invested enterprises shall report investment information to competent commerce departments of the government through the enterprise registration system and the enterprise credit information publicity system, and the administration for market regulation shall forward the above investment information to the competent commerce departments in a timely manner. In addition, the Ministry of Commerce shall set up a foreign investment information reporting system to receive and handle the investment information and inter-departmentally shared information forwarded by the administration for market regulation in a timely manner. The foreign investors or foreign-invested enterprises shall report the investment information by submitting initial reports, change reports, deregistration reports and annual reports, etc.
Furthermore, the Foreign Investment Law provides that foreign-invested enterprises established according to the previous laws regulating foreign investment prior to the implementation of the Foreign Investment Law may maintain their structure and corporate governance within five years after the implementation of the Foreign Investment Law. The Implementing Rules further clarify that such foreign-invested enterprises established prior to the implementation of the Foreign Investment Law may either adjust their organizational forms or organizational structures pursuant to the Company Law or the Partnership Law, or maintain their current structure and corporate governance within five years upon the implementation of the Foreign Investment Law. Since January 1, 2025, if a foreign-invested enterprise fails to adjust its organizational form or organizational structure in accordance with the laws and go through the applicable registrations for changes, the relevant administration for market regulation shall not handle other registrations for such foreign-invested enterprise and shall publicize the relevant circumstances. However, after the organizational forms or organizational structures of a foreign-invested enterprise have been adjusted, the original parties to the Sino-foreign equity or cooperative joint ventures may continue to process such matters as the equity interest transfer, the distribution of income or surplus assets as agreed by the parties in the relevant contracts.
In addition, the Foreign Investment Law and the Implementing Rules also specify other protective rules and principles for foreign investors and their investments in the PRC, including, among others, that local governments shall abide by their commitments to the foreign investors; except for special circumstances, in which case statutory procedures shall be followed and fair and reasonable compensation shall be made in a timely manner, expropriation or requisition of the investment of foreign investors is prohibited; mandatory technology transfer is prohibited, etc.
102
Table of Contents
Regulation Related to Value-Added Telecommunications Services
Regulation on Value-Added Telecommunications Services
The Telecommunications Regulations of the PRC, or the Telecommunications Regulations, promulgated on September 25, 2000 by the State Council of the PRC and most recently amended in February 2016, are the primary regulations governing telecommunications services. Under the Telecommunications Regulations, a telecommunications service provider is required to procure operating licenses from MIIT or its provincial counterparts, prior to the commencement of its operations, or else such operator might be subject to sanctions including corrective orders and warnings from the competent administration authority, fines and confiscation of illegal gains. In case of serious violations, the operator’s websites may be ordered to be closed.
The Telecommunications Regulations categorize all telecommunications services in China as either basic telecommunications services or value-added telecommunications services, and value-added telecommunications services are defined as telecommunications and information services provided through public network infrastructures. The Administrative Measures for Telecommunications Business Operating License promulgated by the MIIT in July 2017 set forth more specific provisions regarding the types of licenses required to operate value-added telecommunications services, the qualifications and procedures for obtaining the licenses and the administration and supervision of these licenses.
A catalogue was issued as an appendix to the Telecommunications Regulations, or the Telecommunications Services Catalogue, which was most recently amended by the MIIT in June 2019. Pursuant to the Telecommunications Services Catalogue, the first category of value-added telecommunications services are divided into four subcategories including the “Internet Data Centre Services” (the “IDC Service”), the “Content Delivery Network Services”, the “Domestic Internet Protocol Virtual Private Network Services” (the “IP-VPN Service”) and the “Internet Access Services” (the “ISP Service”). The second category of value-added telecommunications services includes without limitation the online data process and transaction process service and information services.
In addition, the MIIT promulgated the Circular on Further Regulating Market Access of IDC Service and ISP Service in 2012, or the Circular 552, which further stipulates the detailed requirements on capital, personnel, facility and equipment for conducting IDC and ISP Services business. On January 17, 2017, the MIIT further promulgated the Notice on Cleaning Up and Regulating the Internet Access Service Market, which emphasizes the requirements as specified under Circular 552 and prohibits business operation without licenses, business operation beyond permitted territorial scope and business scope set forth on the licenses and “multi-level sublease” in the market with respect to IDC Service, ISP Service and content delivery network service. The IDC and ISP enterprises shall not sublease the IP addresses, bandwidth or other network access resources they have obtained from basic telecommunication operators in the PRC to other enterprises for operating businesses of IDC Service, ISP Service or other business. According to this notice, enterprises engaged in the businesses of IDC, ISP or content delivery network services shall conduct comprehensive self-inspection and rectify violations of the relevant regulations in a timely manner to ensure their business operations are in compliance with the applicable laws and regulations and the network facilities and network access resources are used in a compliant manner. The regulatory authorities shall urge enterprises in violation of the relevant regulations to make rectifications in a timely manner and take stern actions in accordance with the laws against the enterprises that refuse to make such rectifications, and such enterprises may fail to pass the annual inspection or may be included in the enterprise list of bad credit record, or the licenses or permits of such enterprises may not be renewed upon expiration and their cooperation with the basic telecommunications operators may be adversely affected under serious circumstances.
Regulation on Foreign Investment Restriction on Value-Added Telecommunications Services
Pursuant to the Protocol on the Accession of the PRC effective on November 10, 2001, China’s commitment to open telecommunication business does not include IDC Service, CDN Service, IP-VPN Service and ISP Service. Pursuant to the Mainland and Hong Kong Closer Economic Partnership Agreement and Mainland and Macao Closer Economic Partnership Agreement (collectively, the “CEPA Agreements”), both effective on June 1, 2016, Chinese Mainland has promised to open the aforementioned services to service providers in Hong Kong Special Administrative Region and Macao Special Administrative Region subject to certain limitations.
103
Table of Contents
According to the 2024 Negative List and the currently effective Administrative Regulations on Foreign-Invested Telecommunications Enterprises, as for the value-added telecommunications business types which fall within China’s commitment to the WTO, the ultimate capital contribution percentage by foreign investor(s) in a foreign-invested value-added telecommunications enterprise shall not exceed 50%, except as otherwise stipulated by the state. In Particular, from May 1, 2022, the amended Administrative Regulations on Foreign-Invested Telecommunications Enterprises canceled the qualification requirement on the primary foreign investor in a foreign invested value-added telecommunications enterprise for having a good track record and operational experience in the value-added telecommunications industry as stipulated in the previous version.
In 2006, the predecessor to the MIIT issued the Circular of the Ministry of Information Industry on Strengthening the Administration of Foreign Investment in Value-added Telecommunications Business, according to which a foreign investor in the telecommunications service industry of China must establish a foreign invested enterprise and apply for a telecommunications businesses operation license. This circular further requires that: (i) PRC domestic telecommunications business enterprises must not lease, transfer or sell a telecommunications businesses operation license to a foreign investor through any form of transaction or provide resources, offices and working places, facilities or other assistance to support the illegal telecommunications services operations of a foreign investor; (ii) value-added telecommunications enterprises or their shareholders must directly own the domain names and trademarks used by such enterprises in their daily operations; (iii) each value-added telecommunications enterprise must have the necessary facilities for its approved business operations and maintain such facilities in the regions covered by its license; and (iv) all providers of value-added telecommunications services are required to maintain network and internet security in accordance with the standards set forth in relevant PRC regulations. If a license holder fails to comply with the requirements in the circular and cure such noncompliance, the MIIT or its local counterparts have the discretion to take measures against such license holder, including revoking its license for value-added telecommunications business.
On January 12, 2017, the State Council issued the Notice on Several Measures for Expansion of Opening-up Policy and Active Use of Foreign Capital, which purports to relax restrictions on foreign investment in sectors including services, manufacturing and mining. Specifically, this notice proposes to gradually open up telecommunications, internet, culture, education and transportation industries to foreign investors. On July 25, 2023, the State Council issued the Opinion on Further Optimizing the Environment for Foreign Investment and Increasing Efforts to Attract Foreign Investment, which further proposes to gradually open up value-added telecommunication to foreign investors in more pilot areas. On April 8, 2024, the MIIT promulgated the Notice on the Pilot Program for Expanding the Opening up of Value-added Telecommunications Services. The pilot program will be first carried out in the designated districts in Beijing, Shanghai, Hainan and Shenzhen. In regions approved to carry out the pilot program, restrictions on foreign equity ratios will be removed for internet data centers (IDC), content delivery networks (CDN), internet service providers (ISP), online data processing and transaction processing, information releasing platforms and delivery services included in information services (excluding the operation of internet news information, online publishing, online audio and video, and internet culture), as well as information protection and processing services. The relevant local telecommunication authorities have subsequently published the guidance to implement the aforementioned notice.
Regulation Related to Internet Security and Privacy Protection
The Decision in Relation to Protection of Internet Security enacted by the Standing Committee of the National People’s Congress of China on December 28, 2000, as amended, provides that, among other things, the following activities conducted through the internet, if constituting a criminal act under PRC laws, are subject to criminal punishment: (i) hacking into a computer or system of strategic importance; (ii) intentionally inventing and spreading destructive programs such as computer viruses to attack the computer system and the communications network, thus damaging the computer system and the communications networks; (iii) in violation of State regulations, discontinuing the computer network or the communications service without authorization; (iv) leaking state secrets; (v) spreading false commercial information; or (vi) infringing intellectual property rights through the internet.
The Provisions on Technological Measures for Internet Security Protection, or the Internet Security Protection Measures, promulgated on December 13, 2005 by the Ministry of Public Security require internet service providers and organizations that use interconnection implementing technical measures for internet security protection, like technical measures for preventing any matter or act that may endanger network security, e.g., computer viruses, invasion or attacks to or destruction of the network, to require all internet access service providers to take measures to keep a record of and preserve user registration information. Under these measures, value-added telecommunications services license holders must regularly update information security and content control systems for their websites and must also report any public dissemination of prohibited content to local public security authorities. If a value-added telecommunications services license holder violates these measures, the Ministry of Public Security and the local security bureaus may revoke its operating license and shut down its websites.
104
Table of Contents
On July 1, 2015, the Standing Committee of the National People’s Congress issued the National Security Law, which came into effect on the same day. The National Security Law provides that the state shall safeguard the sovereignty, security and cyber security development interests of the state, and that the state shall establish a national security review and supervision system to review, among other things, foreign investment, key technologies, internet and information technology products and services, and other important activities that are likely to impact the national security of the PRC. On November 7, 2016, the National People’s Congress Standing Committee promulgated the Cybersecurity Law which came into effect on June 1, 2017 and applies to the construction, operation, maintenance and use of networks as well as the supervision and administration of cybersecurity in China. The Cybersecurity Law was latest amended on October 28, 2025 and the amended Cybersecurity Law came into effect on January 1, 2026. The Cybersecurity Law defines “networks” as systems that are composed of computers or other information terminals and relevant facilities used for the purpose of collecting, storing, transmitting, exchanging and processing information in accordance with certain rules and procedures. “Network operators,” who are broadly defined as owners and administrators of networks and network service providers, are subject to various security protection-related obligations, including: (i) complying with security protection obligations in accordance with tiered cybersecurity systems’ protection requirements, which include formulating the internal security management rules and manual, appointing cybersecurity responsible personnel, adopting technical measures to prevent computer viruses and cybersecurity endangering activities, and adopting technical measures to monitor and record network operation status and cybersecurity events; (ii) formulating cybersecurity emergency response plans, timely handling security risks, initiating emergency response plans, taking appropriate remedial measures and reporting to regulatory authorities; and (iii) providing technical assistance and support for public security and national security authorities for protection of national security and criminal investigations in accordance with the law. Network service providers who do not comply with the Cybersecurity Law may be subject to fines, suspension of their businesses, shutdown of their websites and revocation of their business licenses. In addition, the Cybersecurity Law provides that personal information and important data collected and generated by operators of critical information infrastructure in the course of their operations in the PRC should be stored in the PRC, and imposes heightened regulation and additional security obligations on operators of critical information infrastructure. The recently amended Cybersecurity Law strengthens enforcement measures and significantly increases penalties for violations of the law.
On June 10, 2021, the Standing Committee of the National People’s Congress of China promulgated the Data Security Law, which took effect in September 2021. The Data Security Law provides for data security and privacy obligations on entities and individuals carrying out data activities. The Data Security Law also introduces a data classification and hierarchical protection system based on the importance of data in economic and social development, as well as the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, or illegally acquired or used. The appropriate level of protection measures is required to be taken for each respective category of data. For example, a processor of important data shall designate the personnel and the management body responsible for data security, carry out risk assessments for its data processing activities and file the risk assessment reports with the competent authorities. In addition, the Data Security Law provides a national security review procedure for those data activities which may affect national security and imposes export restrictions on certain data and information. We may be required to make further adjustments to our business practices to comply with this law.
On July 30, 2021, the State Council promulgated the Regulations on Security Protection of Critical Information Infrastructure, effective on September 1, 2021. According to these regulations, a “critical information infrastructure” refers to an important network facility and information system in important industries such as, among others, public communications and information services, as well as other important network facilities and information systems that may seriously endanger national security, the national economy, the people’s livelihood, or the public interests in the event of damage, loss of function, or data leakage. The competent governmental authorities and supervision and management authorities of the aforementioned important industries will be responsible for (i) organizing the identification of critical information infrastructures in their respective industries in accordance with certain identification rules, and (ii) promptly notifying the identified operators and the public security department of the State Council of the identification results.
105
Table of Contents
The Administrative Provisions on Security Vulnerability of Network Products were jointly promulgated by the MIIT, the CAC and the Ministry of Public Security on July 12, 2021 and took effect on September 1, 2021. Network product providers, network operators as well as organizations or individuals engaging in the discovery, collection, release and other activities of network product security vulnerability are subject to these provisions and shall establish channels to receive information of security vulnerability of their respective network products and shall examine and fix such security vulnerability in a timely manner. Network product providers are required to report relevant information of security vulnerability of network products with the MIIT within two days and to provide technical support for network product users. Network operators shall take measures to examine and fix security vulnerability after discovering or acknowledging that their networks, information systems or equipment have security loopholes. According to these provisions, the breaching parties may be subject to administrative penalty as regulated in accordance with the Cybersecurity Law.
On December 28, 2021, the Cyberspace Administration of China, together with certain other PRC governmental authorities, promulgated the Cybersecurity Review Measures that replaced the previous version and took effect from February 15, 2022. Pursuant to these measures, the purchase of network products and services by an operator of critical information infrastructure or the data processing activities of a network platform operator that affect or may affect national security will be subject to a cybersecurity review. In addition, any online platform operator possessing over one million users’ individual information must apply for a cybersecurity review before listing abroad. The competent governmental authorities may also initiate a cybersecurity review against the operators if the authorities believe that the network product or service or data processing activities of such operators affect or may affect national security.
To apply for a cybersecurity review, the relevant operators shall submit (i) an application letter, (ii) a report to analyze the impact or the potential impact on national security, (iii) purchase documents, agreements, the draft contracts, and the draft application documents for the initial public offering or similar activity, and (iv) other necessary materials. If the Cybersecurity Review Office deems it necessary to conduct a cybersecurity review, it should complete a preliminary review within 30 business days from the issuance of a written notice to the operator, or 45 business days for complicated cases. Upon the completion of a preliminary review, the Cybersecurity Review Office should reach a review conclusion suggestion and send the review conclusion suggestion to the members for the cybersecurity review mechanism and the relevant authorities for their comments. These authorities shall issue a written reply within 15 business days from the receipt of the review conclusion suggestion. If the Cybersecurity Review Office and these authorities reach a consensus, then the Cybersecurity Review Office shall inform the operator in writing, otherwise, the case will go through a special review procedure. The special review procedure should be completed within 90 business days, or longer for complicated cases.
In the meantime, the PRC regulatory authorities have also enhanced the supervision and regulation on cross-border data transfer. For example, on July 7, 2022, the CAC promulgated the Measures for the Security Assessment of Cross-border Data Transfer, which came into effect on September 1, 2022. These measures require the data processor providing data overseas and falling under any of the specified circumstances apply for the security assessment of cross-border data transfer by the national cybersecurity authority through its local counterpart. On February 22, 2023, the CAC promulgated the Measures on the Standard Contract for Cross-border Transfer of Personal Information, which became effective on June 1, 2023. These measures require personal information processors providing personal information to overseas recipients by entering into standard contracts and falling under any of the specified circumstance to file with the local counterpart of the CAC within ten business days from the effective date of the relevant standard contracts. Furthermore, on March 22, 2024, the CAC promulgated the Provisions on Promoting and Standardizing Cross-Border Data Transfer, which set forth the circumstances exempted from performing the security assessment or filing procedures for cross-border data transfer and further clarify the thresholds and scenarios for data processors to go through these procedures as stipulated under the aforementioned measures. Uncertainties still exist with respect to the interpretation and implementation of these measures in practice and how they will affect our business operation and the value of our securities.
Pursuant to the Decision on Strengthening the Protection of Online Information, issued by the Standing Committee of the National People’s Congress in 2012, and the Order for the Protection of Telecommunication and Internet User Personal Information, issued by the MIIT in 2013, any collection and use of a user’s personal information must be subject to the consent of the user, be legal, rational and necessary and be limited to specified purposes, methods and scopes. An internet information service provider must also keep such information strictly confidential, and is further prohibited from divulging, tampering or destroying any such information, or selling or providing such information to other parties. An internet information service provider is required to take technical and other measures to protect the collected personal information from any unauthorized disclosure, damage or loss. Any violation of these laws and regulations may subject the internet information service provider to warnings, fines, confiscation of illegal gains, revocation of licenses, cancellation of filings, closedown of websites or even criminal liabilities.
106
Table of Contents
Pursuant to the Notice of the Supreme People’s Court, the Supreme People’s Procuratorate and the Ministry of Public Security on Legally Punishing Criminal Activities Infringing upon the Personal Information of Citizens, issued in 2013, and the Interpretation of the Supreme People’s Court and the Supreme People’s Procuratorate on Several Issues regarding Legal Application in Criminal Cases Infringing upon the Personal Information of Citizens, which was issued on May 8, 2017 and took effect on June 1, 2017, the following activities may constitute the crime of infringing upon a citizen’s personal information: (i) providing a citizen’s personal information to specified persons or releasing a citizen’s personal information online or through other methods in violation of relevant national provisions; (ii) providing legitimately collected information relating to a citizen to others without such citizen’s consent (unless the information is processed, not traceable to a specific person and not recoverable); (iii) collecting a citizen’s personal information in violation of applicable rules and regulations when performing a duty or providing services; or (iv) collecting a citizen’s personal information by purchasing, accepting or exchanging such information in violation of applicable rules and regulations. In addition, the Opinions of the Supreme People’s Court, the Supreme People’s Procuratorate, and the Ministry of Public Security on Several Issues Concerning the Application of Criminal Procedures in Handling of Criminal Cases Involving Information Networks, which took effect on September 1, 2022, further provide detailed procedures on facilitating the handling of criminal cases of (i) refusing to perform the obligation of managing the security of the information networks, (ii) illegally using the information networks, or (iii) assisting in the criminal activities of the information networks.
On August 20, 2021, the Standing Committee of the National People’s Congress promulgated the Personal Information Protection Law, which took effect on November 1, 2021. Pursuant to the Personal Information Protection Law, “personal information” refers to any kind of information related to an identified or identifiable individual as electronically or otherwise recorded but excluding the anonymized information. The processing of personal information includes the collection, storage, use, processing, transmission, provision, disclosure and deletion of personal information. The Personal Information Protection Law applies to the processing of personal information of individuals within the territory of the PRC, as well as personal information processing activities outside the territory of PRC, for the purpose of providing products or services to natural persons located within China, for analysing or evaluating the behaviours of natural persons located within China, or for other circumstances as prescribed by laws and administrative regulations. A personal information processor may process the personal information of this individual only under the following circumstances: (i) where consent is obtained from the individual; (ii) where it is necessary for the execution or performance of a contract to which the individual is a party, or where it is necessary for carrying out human resource management pursuant to employment rules legally adopted or a collective contract legally concluded; (iii) where it is necessary for performing a statutory responsibility or statutory obligation; (iv) where it is necessary in response to a public health emergency, or for protecting the life, health or property safety of a natural person in the case of an emergency; (v) where the personal information is processed within a reasonable scope to carry out any news reporting, supervision by public opinions or any other activity for public interest purposes; (vi) where the personal information, which has already been disclosed by an individual or otherwise legally disclosed, is processed within a reasonable scope; or (vii) any other circumstance as provided by laws or administrative regulations. In principle, the consent of an individual must be obtained for the processing of his or her personal information, except under the circumstances of the aforementioned items (ii) to (vii). Where personal information is to be processed based on the consent of an individual, such consent shall be a voluntary and explicit indication of intent given by such individual on a fully informed basis. If laws or administrative regulations provide that the processing of personal information shall be subject to the separate consent or written consent of the individual concerned, such provisions shall prevail. In addition, the processing of the personal information of a minor under 14 years old must obtain the consent by a parent or a guardian of such minor and the personal information processors must adopt special rules for processing personal information of minors under 14 years old. Furthermore, the Personal Information Protection Law stipulates the rules for cross-border transfer of personal information. Any cross-border transfer of personal information is subject to the condition that it is necessary to provide the personal information to a recipient outside the territory of the PRC due to any business need or any other need, as well as the satisfaction of at least one of the following conditions: (i) where a security assessment organized by the national cyberspace administration has been passed; (ii) where a certification of personal information protection has been passed from a professional institution in accordance with the provisions issued by the national cyberspace administration; (iii) where a standard contract formulated by the national cyberspace administration has been entered into with the overseas recipient; or (iv) any other condition prescribed by laws, administrative regulations or any other requirements by the national cyberspace administration. Critical information infrastructure operators and personal information processors who have processed personal information in an amount reaching a threshold prescribed by the national cyberspace administration, must store in the territory of the PRC the personal information collected or generated within the territory of the PRC. If it is necessary to provide such information to an overseas recipient, a security assessment organized by the national cyberspace administration must be passed.
107
Table of Contents
On September 24, 2024, the CAC promulgated the Regulations for the Administration of Network Data Security, which came into effect on January 1, 2025. The Regulations for the Administration of Network Data Security restates and further specifies the legal requirements for personal information, important data, cross-border data transfer, network platform services, and data security. Among others, if the network data processing activities have or may have impacts on national security, such activities shall be subject to national security review in accordance with relevant laws and regulations. Any failure to comply with such requirements may subject us to suspension of services, fines, revocation of relevant business permits or business licenses and other penalties.
Regulation Related to Anti-Monopoly
The PRC Anti-monopoly Law, which was promulgated on August 1, 2008 and most recently amended on June 24, 2022, prohibits monopolistic conduct such as entering into monopoly agreements, abusing market dominance and concentration of undertakings conducted illegally that may have the effect of eliminating or restricting competition. The amended PRC Anti-monopoly Law increases the fines for illegal concentration of business operators to “no more than ten percent of its preceding year’s sales revenue if the concentration of business operator has or may have an effect of excluding or limiting competition; or a fine of up to RMB5 million if the concentration of business operator does not have an effect of excluding or limiting competition.” The amended PRC Anti-monopoly Law also proposes for the relevant authority to investigate any concentration where there is evidence that such concentration has or may have the effect of eliminating or restricting competition, even if such concentration does not reach the filing threshold. In addition, the amended PRC Anti-monopoly Law introduces a “stop-clock mechanism” which may prolong the review process for the concentration.
On September 11, 2020, the Anti-Monopoly Commission of the State Council issued Anti-Monopoly Compliance Guideline for Operators, which requires operators to establish anti-monopoly compliance management systems under the PRC Anti-Monopoly Law to manage anti-monopoly compliance risks. On February 7, 2021, the Anti-Monopoly Committee of the State Council promulgated the Anti-Monopoly Guidelines for the Internet Platform Economy Sector, aiming to provide guidelines for supervising and prohibiting monopolistic conduct in connection with the internet platform business operations and further elaborate on the factors for recognizing such monopolistic conduct in the internet platform industry as well as concentration filing procedures for business operators, including those involving variable interest entities. Pursuant to these guidelines, the methods of an internet platform collecting or using the privacy information of internet users may also be one of the factors to be considered for analyzing and recognizing monopolistic conducts in the internet platform industry. For example, whether the relevant business operator compulsorily collects unnecessary user information may be considered to analyze whether there is a bundled sale or additional unreasonable trading condition, which is one of the behaviors constituting abuse of dominant market position. In addition, factors including, among others, providing differentiated transaction prices or other transaction conditions for consumers with different payment ability based on consumption preferences and usage habits analyzed using big data and algorithms is also one of the behaviors constituting abuse of dominant market position. Furthermore, whether the relevant business operators are required to “choose one” among the internet platform and its competitive platforms may be considered to analyze whether such internet platform operator with dominant market position abuses its dominant market position and excludes or restricts market competition. There are still uncertainties as to the interpretation and implementation of these guidelines in practice.
108
Table of Contents
On March 10, 2023, the SAMR promulgated the Provisions on Prohibiting Monopoly Agreements, the Provisions on Prohibiting Abuse of Dominant Market Positions, the Provisions on the Examination of Concentrations of Undertakings and the Provisions on Prohibiting the Acts of Eliminating or Restricting Competition by Abuse of Administrative Power, all of which came into effect on April 15, 2023. On June 25, 2023, the SAMR promulgated the Provisions on Prohibition of the Abuse of Intellectual Property to Exclude or Restrict Competition, which came into effect on August 1, 2023. These provisions specify and refine the relevant provisions of the Anti-monopoly Law. For example, these provisions specify the conditions for suspending the review period for calculating the concentration of undertakings, clarify the judgment factors of “control” and “implementation of concentration” in the review of concentration of undertakings, optimize the calculation of turnover of undertakings involved in concentration, etc. In addition, factors for determining whether a concentration has been implemented include, but are not limited to, the completion of market entity registration or right holder change registration, assignment of senior management, actual participation in business decisions and management, exchange of sensitive information with other undertakings, and substantial integration of business. Besides, an operator with a leading market position may be deemed to have a dominant market position when the relevant conditions are met. Such conditions include an undertaking’s capability to control the upstream and downstream markets, its financial and technological resources, the level of difficulty for other undertakings to enter relevant market, consistency of undertaking behaviors, market structure, transparency of relevant markets, homogeneity of relevant commodities, etc. These provisions further emphasize that operators with dominant market positions shall not utilize intellectual properties, data, algorithms, technologies and rules of the platform, among others, to conduct acts of abusing their dominant market positions as stipulated thereunder. In addition, these provisions also clarify the legal responsibility of relevant subjects under different circumstances. For example, according to the Provisions on Prohibiting Monopoly Agreements, where the legal representative, principal responsible person and directly responsible person of an undertaking assume individual responsibility for conclusion of a monopoly agreement, and if such person proactively reports the information on conclusion of the monopoly agreement and provides important evidences to the competent anti-monopoly enforcement authorities, the provisions of the mitigation of or exemption from penalties thereunder may apply.
Regulation Related to Intellectual Property
Patent
Patents in the PRC are principally protected under the Patent Law of the PRC. The duration of a patent right is either 10 years in the case of utility models, 15 years in the case of designs, or 20 years in the case of an invention from the date of application.
Copyright
Copyright in the PRC, including copyrighted software, is principally protected under the Copyright Law of the PRC and related rules and regulations. Under the Copyright Law, the term of protection for copyrighted software is 50 years. The Regulation on the Protection of the Right to Communicate Works to the Public over Information Networks, as most recently amended on January 30, 2013, provides specific rules on fair use, statutory license, and a safe harbor for use of copyrights and copyright management technology and specifies the liabilities of various entities for violations, including copyright holders, libraries and internet service providers.
Trademark
Registered trademarks are protected under the Trademark Law of the PRC and related rules and regulations. Trademarks are registered with the State Intellectual Property Office, formerly the Trademark Office of the SAIC. Where registration is sought for a trademark that is identical or similar to another trademark which has already been registered or given preliminary examination and approval for use in the same or similar category of commodities or services, the application for registration of this trademark may be rejected. Trademark registrations are effective for a renewable 10-year period, unless otherwise revoked.
Domain Name
Domain names are protected under the Administrative Measures on Internet Domain Names promulgated by the MIIT on August 24, 2017 and effective as of November 1, 2017. Domain name registrations are handled through domain name service agencies established under the relevant regulations, and applicants become domain name holders upon successful registration.
109
Table of Contents
Regulation Related to Employment, Social Insurance and Housing Fund
Pursuant to the PRC Labor Law and the PRC Labor Contract Law, employers must execute written labor contracts with full-time employees. All employers must comply with local minimum wage standards. Violations of the PRC Labor Contract Law and the PRC Labor Law may result in the imposition of fines and other administrative and criminal liability in the case of serious violations.
In addition, according to the PRC Social Insurance Law and the Regulations on the Administration of Housing Funds, employers in China must provide employees with welfare schemes covering pension insurance, unemployment insurance, maternity insurance, work-related injury insurance, and medical insurance and housing funds.
Regulation Related to Foreign Exchange and Dividend Distribution
Regulation on Foreign Currency Exchange
The principal regulations governing foreign currency exchange in China are the Foreign Exchange Administration Regulations, most recently amended in 2008. Under PRC foreign exchange regulations, payments of current account items, such as profit distributions, interest payments and trade and service-related foreign exchange transactions, can be made in foreign currencies without prior approval from the State Administration of Foreign Exchange, or SAFE, by complying with certain procedural requirements. By contrast, approval from or registration with appropriate government authorities is required where RMB is to be converted into foreign currency and remitted out of China to pay capital account items, such as direct investments, repayment of foreign currency-denominated loans, repatriation of investments and investments in securities outside of China.
In 2012, SAFE promulgated the Circular of Further Improving and Adjusting Foreign Exchange Administration Policies on Foreign Direct Investment, or Circular 59, which substantially amends and simplifies the current foreign exchange procedure. Pursuant to Circular 59, the opening of various special purpose foreign exchange accounts, such as pre-establishment expenses accounts, foreign exchange capital accounts and guarantee accounts, the reinvestment of RMB proceeds derived by foreign investors in the PRC, and remittance of foreign exchange profits and dividends by a foreign-invested enterprise to its foreign shareholders no longer require the approval or verification of SAFE, and multiple capital accounts for the same entity may be opened in different provinces, which was not possible previously. In 2013, SAFE specified that the administration by SAFE or its local branches over direct investment by foreign investors in the PRC must be conducted by way of registration and banks must process foreign exchange business relating to the direct investment in the PRC based on the registration information provided by SAFE and its branches. In February 2015, SAFE promulgated the Notice on Further Simplifying and Improving the Administration of the Foreign Exchange Concerning Direct Investment, or SAFE Notice 13. Instead of applying for approvals regarding foreign exchange registrations of foreign direct investment and overseas direct investment from SAFE, entities and individuals may apply for such foreign exchange registrations from qualified banks. The qualified banks, under the supervision of SAFE, may directly review the applications and conduct the registration.
110
Table of Contents
In March 2015, SAFE promulgated the Circular of the SAFE on Reforming the Management Approach regarding the Settlement of Foreign Capital of Foreign-invested Enterprise, or Circular 19, which expands a pilot reform of the administration of the settlement of the foreign exchange capitals of foreign-invested enterprises nationwide. Circular 19 replaced both the Circular of the SAFE on Issues Relating to the Improvement of Business Operations with Respect to the Administration of Foreign Exchange Capital Payment and Settlement of Foreign-invested Enterprises, or Circular 142, and the Circular of the SAFE on Issues concerning the Pilot Reform of the Administrative Approach Regarding the Settlement of the Foreign Exchange Capitals of Foreign-invested Enterprises in Certain Areas, or Circular 36. Circular 19 allows all foreign-invested enterprises established in the PRC to settle their foreign exchange capital on a discretionary basis according to the actual needs of their business operation, provides the procedures for foreign invested companies to use Renminbi converted from foreign currency-denominated capital for equity investments and removes certain other restrictions that had been provided in Circular 142. However, Circular 19 continues to prohibit foreign-invested enterprises from, among other things, using RMB funds converted from their foreign exchange capital for expenditure beyond their business scope and providing entrusted loans or repaying loans between nonfinancial enterprises. SAFE promulgated the Notice of the State Administration of Foreign Exchange on Reforming and Standardizing the Foreign Exchange Settlement Management Policy of Capital Account, or Circular 16, effective June 2016, which reiterates some of the rules set forth in Circular 19. Circular 16 provides that discretionary foreign exchange settlement applies to foreign exchange capital, foreign debt offering proceeds and remitted foreign listing proceeds, and the corresponding RMB capital converted from foreign exchange may be used to extend loans to related parties or repay inter-company loans (including advances by third parties). However, there are substantial uncertainties with respect to Circular 16’s interpretation and implementation in practice. Circular 19 or Circular 16 may delay or limit us from using the proceeds of offshore offerings to make additional capital contributions to our PRC subsidiaries and any violations of these circulars could result in severe monetary or other penalties.
In January 2017, SAFE promulgated the Circular on Further Improving Reform of Foreign Exchange Administration and Optimizing Genuineness and Compliance Verification, or Circular 3, which stipulates several capital control measures with respect to the outbound remittance of profits from domestic entities to offshore entities, including (i) banks must check whether the transaction is genuine by reviewing board resolutions regarding profit distribution, original copies of tax filing records and audited financial statements and (ii) domestic entities must retain income to account for previous years’ losses before remitting any profits. Moreover, pursuant to Circular 3, domestic entities must explain in detail the sources of capital and how the capital will be used, and provide board resolutions, contracts and other proof as a part of the registration procedure for outbound investment.
On October 23, 2019, SAFE issued Circular of the State Administration of Foreign Exchange on Further Promoting the Facilitation of Cross-border Trade and Investment, or the Circular 28, which took effect on the same day, and was amended on December 4, 2023, by the Circular on Further Deepening the Reform to Facilitate Cross-border Trade and Investment. Circular 28 allows non-investment foreign-invested enterprises to use their capital funds to make equity investments in China, provided that such investments do not violate the effective special entry management measures for foreign investment (negative list) and the target investment projects are genuine and in compliance with laws. Uncertainties still exist with respect to its interpretation and implementation. The Notice on Further Deepening Reforms to Promote the Facilitation of Trade and Investment provides that qualified high-tech, “professional, sophisticated, unique and new” and technology-based small and medium-sized enterprises located in specified provinces or cities may borrow foreign debt on their own, provided the amount of debt does not exceed the equivalent of US$10 million. In addition, this notice restructured the asset realization account of capital accounts to the settlement account of capital accounts. Funds denominated in foreign currency received in consideration of an equity transfer by a domestic equity transferor (including entities and individuals) from domestic parties, as well as the foreign exchange funds raised by domestic enterprises through overseas listing may be directly remitted to the settlement account of capital accounts. Funds in the settlement account of capital accounts may be settled and used at the discretion of the account holder.
Regulation on Dividend Distributions
The principal laws, rule and regulations governing dividends distribution by companies in the PRC are the PRC Company Law, which applies to both PRC domestic companies and foreign-invested companies, and the Foreign Investment Law and its implementing rules, which apply to foreign-invested companies. Under these laws, regulations and rules, both domestic companies and foreign-invested companies in the PRC are required to set aside as general reserves at least 10% of their after-tax profit, until the cumulative amount of their reserves reaches 50% of their registered capital. PRC companies are not permitted to distribute any profits until any losses from prior fiscal years have been offset. Profits retained from prior fiscal years may be distributed together with distributable profits from the current fiscal year.
111
Table of Contents
Regulation on Foreign Exchange Registration of Overseas Investment by PRC Residents
In 2014, SAFE issued the SAFE Circular on Relevant Issues Relating to Domestic Resident’s Investment and Financing and Roundtrip Investment through Special Purpose Vehicles, or SAFE Circular 37, replacing the SAFE Circular on Issues Concerning the Regulation of Foreign Exchange in Equity Finance and Return Investments by Domestic Residents through Offshore Special Purpose Vehicles, or SAFE Circular 75. SAFE Circular 37 regulates foreign exchange matters in relation to the use of special purpose vehicles by PRC residents or entities to seek offshore investment and financing or conduct round trip investment in China. Under SAFE Circular 37, a “special purpose vehicle” refers to an offshore entity established or controlled, directly or indirectly, by PRC residents or entities for the purpose of seeking offshore financing or making offshore investment, using legitimate onshore or offshore assets or interests, while “round trip investment” refers to direct investment in China by PRC residents or entities through special purpose vehicles, namely, establishing foreign-invested enterprises to obtain ownership, control rights and management rights. SAFE Circular 37 provides that, before making a contribution into a special purpose vehicle, PRC residents or entities are required to complete foreign exchange registration with SAFE or its local branch.
In 2015, SAFE promulgated the Notice on Further Simplifying and Improving the Administration of the Foreign Exchange Concerning Direct Investment. This notice has amended SAFE Circular 37 by requiring PRC residents or entities to register with qualified banks rather than SAFE or its local branch in connection with their establishment or control of an offshore entity established for the purpose of overseas investment or financing. PRC residents or entities who had contributed legitimate onshore or offshore interests or assets to special purpose vehicles but had not registered as required before the implementation of the SAFE Circular 37 must register their ownership interests or control in the special purpose vehicles with qualified banks. An amendment to the registration is required if there is a material change with respect to the special purpose vehicle registered, such as any change of basic information (including change of the PRC residents, name and operation term), increases or decreases in investment amount, transfers or exchanges of shares, and mergers or divisions. Failure to comply with the registration procedures set forth in SAFE Circular 37 and the subsequent notice, or making misrepresentations or failing to disclose the control of the foreign-invested enterprise that is established through round-trip investment, may result in restrictions being imposed on the foreign exchange activities of the relevant foreign-invested enterprise, including payment of dividends and other distributions, such as proceeds from any reduction in capital, share transfer or liquidation, to its offshore parent or affiliate, and the capital inflow from the offshore parent, and may also subject relevant PRC residents or entities to penalties under PRC foreign exchange administration regulations.
Regulation Related to Stock Incentive Plans
In February 2012, SAFE promulgated the Notice on Foreign Exchange Administration of PRC Residents Participating in Share Incentive Plans of Offshore Listed Companies, or the Stock Option Rules, replacing the previous rules issued by SAFE in March 2007. Under the Stock Option Rules and other relevant rules and regulations, domestic individuals, which means the PRC residents and non-PRC citizens residing in China for a continuous period of not less than one year, subject to a few exceptions, who participate in a stock incentive plan in an overseas publicly listed company are required to register with SAFE or its local branches and complete certain other procedures. Participants of a stock incentive plan who are PRC residents must retain a qualified PRC agent, which could be a PRC subsidiary of the overseas publicly listed company or another qualified institution selected by the PRC subsidiary, to conduct the SAFE registration and other procedures with respect to the stock incentive plan on behalf of its participants. The participants must also retain an overseas entrusted institution to handle matters in connection with their exercise of stock options, the purchase and sale of corresponding stocks or interests and fund transfers. In addition, the PRC agent is required to amend the SAFE registration with respect to the stock incentive plan if there is any material change to the stock incentive plan, the PRC agent or the overseas entrusted institution or other material changes. The PRC agents must, on behalf of the PRC residents who have the right to exercise the employee share options, apply to SAFE or its local branches for an annual quota for the payment of foreign currencies in connection with the PRC residents’ exercise of the employee share options. The foreign exchange proceeds received by the PRC residents from the sale of shares under the stock incentive plans granted and dividends distributed by the overseas listed companies must be remitted into the bank accounts in the PRC opened by the PRC agents before distribution to such PRC residents. In addition, SAFE Circular 37 provides that PRC residents who participate in a share incentive plan of an overseas unlisted special purpose company may register with SAFE or its local branches before exercising rights.
112
Table of Contents
Regulation Related to Tax
Enterprise Income Tax
Under the Enterprise Income Tax Law of the PRC, or the EIT Law, which became effective on January 1, 2008 and was subsequently amended on February 24, 2017 and December 29, 2018, and its implementing rules, enterprises are classified as resident enterprises and non-resident enterprises. PRC resident enterprises typically pay an enterprise income tax at the rate of 25% while non-PRC resident enterprises without any branches in the PRC should pay an enterprise income tax in connection with their income from the PRC at the tax rate of 10%. An enterprise established outside of the PRC with its “de facto management bodies” located within the PRC is considered a “resident enterprise,” meaning that it can be treated in a manner similar to a PRC domestic enterprise for enterprise income tax purposes. The implementing rules of the EIT Law define a de facto management body as a managing body that in practice exercises “substantial and overall management and control over the production and operations, personnel, accounting, and properties” of the enterprise. Enterprises qualified as “High and New Technology Enterprises” are entitled to a 15% enterprise income tax rate rather than the 25% uniform statutory tax rate. The preferential tax treatment continues as long as an enterprise can retain its “High and New Technology Enterprise” status.
The EIT Law and the implementation rules provide that an income tax rate of 10% should normally be applicable to dividends payable to investors that are “non-resident enterprises,” and gains derived by such investors, which (a) do not have an establishment or place of business in the PRC or (b) have an establishment or place of business in the PRC, but the relevant income is not effectively connected with the establishment or place of business to the extent such dividends and gains are derived from sources within the PRC. Such income tax on the dividends may be reduced pursuant to a tax treaty between China and other jurisdictions. Pursuant to the Arrangement Between the Mainland of China and the Hong Kong Special Administrative Region for the Avoidance of Double Taxation on Income, or the Double Tax Avoidance Arrangement, and other applicable PRC laws, if a Hong Kong resident enterprise is determined by the competent PRC tax authority to have satisfied the relevant conditions and requirements under such Double Tax Avoidance Arrangement and other applicable laws, the 10% withholding tax on the dividends the Hong Kong resident enterprise receives from a PRC resident enterprise may be reduced to 5% upon receiving approval from the in-charge tax authority. However, based on the Notice on Certain Issues with Respect to the Enforcement of Dividend Provisions in Tax Treaties issued on February 20, 2009 by the State Taxation Administration, if the relevant PRC tax authorities determine, in their discretion, that a company benefits from such reduced income tax rate due to a structure or arrangement that is primarily tax-driven, such PRC tax authorities may adjust the preferential tax treatment; and based on the Announcement on Relevant Issues Concerning the “Beneficial Owners” in Tax Treaties issued on February 3, 2018 by the State Taxation Administration and effective from April 1, 2018, which replaces the Notice on the Interpretation and Recognition of Beneficial Owners in Tax Treaties and the Announcement on the Recognition of Beneficial Owners in Tax Treaties by the State Taxation Administration, comprehensive analysis based on the stipulated factor therein and actual circumstances shall be adopted when recognizing the “beneficial owner” and agents and designated wire beneficiaries are specifically excluded from being recognized as “beneficial owners.”
Value-added Tax
Pursuant to the Value-Added Tax Law of the PRC, as latest amended by the SCNPC on December 25, 2024, which came into effect on January 1, 2026, and the Regulations for the Implementation of the Value-Added Tax Law of the PRC, issued by the State Council on December 25, 2024 and came into effect on January 1, 2026, any entity or individual engaged in the sales of goods, provision of processing, repairs and replacement services and importation of goods into China is generally required to pay a value-added tax, or VAT, for revenues generated from sales of products, while qualified input VAT paid on taxable purchase can be offset against such output VAT. The general value-added tax rate applicable to the sale or importation of goods is 13%, 9% and 6%.
Furthermore, pursuant to the Announcement on the VAT Reduction and Exemption Policy for Small-scale VAT Taxpayers issued and implemented by the Ministry of Finance and the State Taxation Administration on August 1, 2023, the VAT is exempted for small-scale VAT taxpayers with monthly sales of less than RMB100,000 (inclusive). For taxable sales income applicable to small-scale VAT taxpayers at a rate of 3%, the VAT shall be levied at a reduced rate of 1%.
113
Table of Contents
M&A Rules and Overseas Listings
On August 8, 2006, six PRC regulatory agencies, including the China Securities Regulatory Commission, or the CSRC, adopted the Regulations on Mergers of Domestic Enterprises by Foreign Investors, or the M&A Rules, which became effective on September 8, 2006 and were amended on June 22, 2009. Foreign investors shall comply with the M&A Rules when they purchase equity interests of a domestic company or subscribe the increased capital of a domestic company, thus changing the nature of the domestic company into a foreign-invested enterprise; or when the foreign investors establish a foreign-invested enterprise in the PRC, purchase the assets of a domestic company and operate the assets; or when the foreign investors purchase the asset of a domestic company, establish a foreign-invested enterprise by injecting such assets and operate the assets. The M&A Rules purport, among other things, to require offshore special purpose vehicles formed for overseas listing purposes through acquisitions of PRC domestic companies and controlled by PRC companies or individuals, to obtain the approval of the CSRC prior to publicly listing their securities on an overseas stock exchange.
Furthermore, The General Office of the CPC Central Committee and the General Office of the State Council issued Opinions on Strictly Cracking Down on Illegal Securities Activities in accordance with the Law, which were available to the public on July 6, 2021 and emphasized the need to strengthen the administration over illegal securities activities and the supervision on overseas listings by China-based companies, and proposed to take effective measures, such as promoting the construction of relevant regulatory systems to deal with the risks and incidents faced by China-based overseas-listed companies, and provided that the special provisions of the State Council on overseas offering and listing by those companies limited by shares will be revised and therefore the duties of domestic industry competent authorities and regulatory authorities will be clarified.
On February 17, 2023, the CSRC promulgated the Overseas Listing Trial Measures, and relevant five guidelines on the application of Regulatory Rules, which took effect from March 31, 2023, requiring Chinese domestic companies’ overseas securities offerings or listings be filed with the CSRC. The Overseas Listing Trial Measures clarify the scope of overseas offerings or listings by Chinese domestic companies which are subject to the filing and reporting requirements thereunder, and provide, among others, that Chinese domestic companies that have already directly or indirectly offered and listed securities in overseas markets prior to the effectiveness of the Overseas Listing Trial Measures shall fulfil their filing obligations and report relevant information to the CSRC within three working days after the completion of any subsequent securities offering on the same overseas market, and follow the relevant reporting requirements within three working days upon the occurrence and public disclosure of any specified circumstances provided thereunder, including (i) change of control; (ii) investigations or sanctions imposed by overseas securities regulatory agencies or other relevant competent authorities; (iii) change of listing status or transfer of listing segment; (iv) voluntary or mandatory delisting. In addition, where the main business of an issuer undergoes material change after overseas offering and listing, and is therefore beyond the scope of business stated in the filing documents, such issuer shall follow the relevant reporting requirements within three working days after occurrence of the changes. For violations of these provisions or measures, the competent Chinese authorities may impose administrative regulatory measures, such as orders for correction, warnings, fines, and may pursue legal liability in accordance with law.
Furthermore, on February 24, 2023, the CSRC, together with certain other PRC governmental authorities, promulgated the Provisions on Strengthening Confidentiality and Archives Administration of Overseas Securities Offering and Listing by Domestic Companies (“Revised Confidentiality and Archives Administration Provisions”), which came into effect on March 31, 2023. According to the Revised Confidentiality and Archives Administration Provisions, Chinese companies that directly or indirectly conduct overseas offerings and listings, shall strictly abide by the relevant laws and regulations on confidentiality when providing or publicly disclosing, either directly or through their overseas listed entities, documents and materials to securities services providers such as securities companies and accounting firms or overseas regulators in the process of their overseas offering and listing. In the event such documents or materials contain state secrets or working secrets of government agencies, the Chinese companies shall first obtain approval from competent authorities according to law, and file with the secrecy administrative department at the same level with the approving authority; in the event that such documents or materials, if divulged, will jeopardize national security or public interest, the Chinese companies shall strictly fulfill relevant procedures stipulated by applicable national regulations. The Chinese companies shall also provide a written statement of the specific state secrets and sensitive information provided when providing documents and materials to securities companies and securities service providers, and the securities companies and securities service providers shall properly retain such written statements for inspection. According to the Revised Confidentiality and Archives Administration Provisions, where overseas securities regulators or relevant competent authorities request to inspect, investigate or collect evidence from Chinese domestic companies concerning their overseas offering and listing or their securities firms and securities service providers that undertake securities business for such Chinese domestic companies, such inspection, investigation and evidence collection must be conducted under the cross-border regulatory cooperation mechanism, and the CSRC or competent authorities of the Chinese government will provide necessary assistance pursuant to bilateral and multilateral cooperation mechanism.
114
Table of Contents
We cannot assure you that we will not be required to obtain the approval of or complete the filing or other administrative procedures with the CSRC or potentially other regulatory authorities to maintain the listing status of the ADSs on the Nasdaq and the ordinary shares on the Hong Kong Stock Exchange or to conduct offerings of securities in the future. We have been closely monitoring regulatory developments in China regarding any necessary approvals, filings or other administrative procedures from the CSRC or other PRC regulatory authorities required for overseas securities offerings.
As of the date of this annual report, we have not received any inquiry, notice, warning, sanctions or regulatory objection to our listing status from the CSRC.
4.C. Organizational Structure
The following diagram illustrates our corporate structure as of the date of this annual report, including our significant subsidiaries and significant variable interest entities, and their equity interest holding.
Notes:
(1) Zhuhai Kingsoft Cloud is held as to 79.60% and 20.40% by Beijing Kingsoft Digital Entertainment Technology Co., Ltd. and Ms. Qiu Weiqin, who is a family member of a director of Kingsoft Corporation, respectively, as registered owners. Beijing Kingsoft Digital Entertainment Technology Co., Ltd. is ultimately owned as to 80% and 20% by Ms. Qiu Weiqin and Ms. Lei Peili who is a family member of Mr. Lei Jun, the chairman of our Board.
(2) Kingsoft Cloud Information is held as to 80% and 20% by Ms. Qiu Weiqin and Mr. Tao Zou, our executive director and acting CEO, respectively, as registered owners.
115
Table of Contents
Contractual Arrangements with the VIEs and Their Respective Shareholders
Current PRC laws and regulations impose certain restrictions or prohibitions on foreign ownership of companies that engage in value-added telecommunication services. We are an exempted company with limited liability incorporated in the Cayman Islands. Our PRC subsidiaries, Beijing Kingsoft Cloud and Yunxiang Zhisheng are considered foreign-invested enterprises. To comply with PRC laws and regulations, we primarily conduct our business in China through the VIEs, Zhuhai Kingsoft Cloud and Kingsoft Cloud Information, and their subsidiaries, based on a series of contractual arrangements. Through these contractual arrangements, the nominee shareholders of the VIEs effectively assigned all of their voting rights underlying their equity interests in the VIEs to the Company, and therefore, the Company has the power to direct the activities of the VIEs that most significantly impact its economic performance. The Company is obligated to absorb losses of the variable interest entities that could potentially be significant to the variable interest entities through providing unlimited financial support to the variable interest entities or is entitled to receive economic benefits from the variable interest entities that could potentially be significant to the variable interest entities through the exclusive technology consulting and service fees. As a result of these contractual arrangements, the Company is determined to be the primary beneficiary of these variable interest entities only for accounting purposes and we consolidate these variable interest entities under U.S. GAAP. As a result of these contractual arrangements, we are considered the primary beneficiary of the VIEs for accounting purposes and consolidate their operating results in our financial statements under U.S. GAAP, to the extent the conditions for consolidation of VIEs under U.S. GAAP are satisfied.
The following is a summary of the contractual arrangements by and among Beijing Kingsoft Cloud, Zhuhai Kingsoft Cloud, the shareholders of Zhuhai Kingsoft Cloud and the contractual arrangements by and among Yunxiang Zhisheng, Kingsoft Cloud Information and the shareholders of Kingsoft Cloud Information. For the complete text of these contractual arrangements, please see the copies filed as exhibits to the registration statement filed with the SEC of which this annual report forms a part.
Exclusive Consultation and Technical Service Agreement
Under the exclusive consultation and technical service agreement dated November 9, 2012, as amended and supplemented on November 29, 2019 and July 15, 2022, Beijing Kingsoft Cloud has agreed to exclusively provide the following services (among others) to Zhuhai Kingsoft Cloud:
● the licensing of software, copyrights and know-how legally owned by Beijing Kingsoft Cloud;
● the provision of comprehensive consultancy services related to business operation, management and technology;
● the development, maintenance and updates of hardware and database;
● the development of application software and related operational support and updates;
● the provision of technical training for employees;
● the collection and research of technical information; and
● the provision of other related services as required by Zhuhai Kingsoft Cloud from time to time.
Zhuhai Kingsoft Cloud has agreed to annually pay service fees equal to 100% of its revenues for the year deducting costs in the same period as agreed by both parties, and pay service fees for certain services as required by Zhuhai Kingsoft Cloud from time to time. The service fees are adjustable at the sole discretion of Beijing Kingsoft Cloud. The exclusive consultation and technical service agreement shall remain effective for 20 years from November 9, 2012 unless expressly provided otherwise or Beijing Kingsoft Cloud unilaterally decides to terminate the exclusive consultation and technical service agreement. Beijing Kingsoft Cloud can unilaterally renew this agreement for a further period determined by itself.
116
Table of Contents
On July 18, 2018, Kingsoft Cloud Information and Yunxiang Zhisheng entered into an exclusive consultation and technical service agreement, which was later amended and supplemented on November 29, 2019 and July 15, 2022 and contains terms substantially similar to the exclusive consultation and technical service agreement described above. With the change of the shareholding structure of Kingsoft Cloud Information, where Mr. Tao Zou replaced Mr. Yulin Wang as a registered shareholder of Kingsoft Cloud Information, the original exclusive consultant and technical service agreement entered into between Kingsoft Cloud Information and Yunxiang Zhisheng was terminated on August 24, 2022. On the same day, a new exclusive consultant and technical service agreement with substantially the same terms was entered into between Kingsoft Cloud Information and Yunxiang Zhisheng.
Loan Agreements
On November 9, 2012 and June 20, 2014, Ms. Weiqin Qiu and Beijing Kingsoft Cloud entered into loan agreements, as amended and supplemented on November 29, 2019, under which Beijing Kingsoft Cloud agreed to provide Ms. Weiqin Qiu interest-free loans. Under these loan agreements, the loans shall be repaid by transferring Ms. Weiqin Qiu’s equity interest in Zhuhai Kingsoft Cloud to Beijing Kingsoft Cloud or its designee.
On July 18, 2018, Mr. Yulin Wang and Ms. Weiqin Qiu entered into a loan agreement with Yunxiang Zhisheng, under which Yunxiang Zhisheng agreed to provide Mr. Yulin Wang and Ms. Weiqin Qiu an interest-free loan. This agreement was later amended and supplemented on November 29, 2019 and July 15, 2022, and contains terms substantially similar to the loan agreements described above. With the change of the shareholding structure of Kingsoft Cloud Information, where Mr. Tao Zou replaced Mr. Yulin Wang as a registered shareholder of Kingsoft Cloud Information, the original loan agreement entered into among Mr. Yulin Wang, Ms. Weiqin Qiu and Yunxiang Zhisheng was terminated on August 24, 2022. On the same day, a new loan agreement with substantially the same terms was entered into among Mr. Tao Zou, Ms. Weiqin Qiu and Yunxiang Zhisheng.
Equity Pledge Agreement
Each of Ms. Weiqin Qiu and Beijing Kingsoft Digital Entertainment Technology Co., Ltd., or Kingsoft Digital, the shareholders of Zhuhai Kingsoft Cloud, has entered into an equity pledge agreement with Beijing Kingsoft Cloud and Zhuhai Kingsoft Cloud on June 20, 2014. Under the equity pledge agreement, Ms. Weiqin Qiu and Kingsoft Digital pledged their respective equity interest in Zhuhai Kingsoft Cloud to Beijing Kingsoft Cloud to secure obligations under the applicable loan agreements, exclusive purchase option agreement, shareholder voting right trust agreement, and exclusive consultation and technical service agreement. Ms. Weiqin Qiu and Kingsoft Digital further agreed not to transfer or pledge their equity interest in Zhuhai Kingsoft Cloud without the prior written consent of Beijing Kingsoft Cloud. The equity pledge agreement will remain binding until the pledgers, Ms. Weiqin Qiu and Kingsoft Digital, as the case may be, discharge all of their obligations under the above-mentioned agreements. As of the date of this annual report, the equity pledges under the equity pledge agreement have been registered with the competent PRC regulatory authority.
On July 18, 2018, Mr. Yulin Wang and Ms. Weiqin Qiu entered into an equity pledge agreement with Yunxiang Zhisheng and Kingsoft Cloud Information, which was amended and supplemented on July 15, 2022, and contains terms substantially similar to the equity pledge agreement described above. With the change of the shareholding structure of Kingsoft Cloud Information, where Mr. Tao Zou replaced Mr. Yulin Wang as a registered shareholder of Kingsoft Cloud Information, the original equity pledge agreement entered into among Mr. Yulin Wang, Ms. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information was terminated on August 24, 2022. On the same day, a new equity pledge agreement with substantially the same terms was entered into among Mr. Tao Zou, Mr. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information. As of the date of this annual report, the equity pledges under the equity pledge agreement dated August 24, 2022 have been registered with the competent PRC regulatory authority.
117
Table of Contents
Exclusive Purchase Option Agreement
Ms. Weiqin Qiu and Kingsoft Digital, the shareholders of Zhuhai Kingsoft Cloud, entered into an exclusive purchase option agreement with Beijing Kingsoft Cloud and Zhuhai Kingsoft Cloud on June 20, 2014, which was later amended and supplemented on November 29, 2019. Under the exclusive purchase option agreement, Ms. Weiqin Qiu granted Beijing Kingsoft Cloud or its designee an option to purchase her equity interest in Zhuhai Kingsoft Cloud at a price equal to the higher of the amount of the loan provided to Ms. Weiqin, and the minimum amount of consideration permitted by PRC law, and Kingsoft Digital granted Beijing Kingsoft Cloud or its designee an option to purchase its equity interest in Zhuhai Kingsoft Cloud at a price equal to the higher of RMB1 and the minimum amount of consideration permitted by PRC law. Ms. Weiqin Qiu and Kingsoft Digital also granted Beijing Kingsoft Cloud or its designee an option to purchase all or a portion of the assets of Zhuhai Kingsoft Cloud for the minimum amount of consideration permitted by PRC law. Ms. Weiqin Qiu and Kingsoft Digital also agreed not to transfer or mortgage any equity interest in or dispose of or cause the management to dispose of any material assets of Zhuhai Kingsoft Cloud without the prior written consent of Beijing Kingsoft Cloud. The exclusive purchase option agreement shall remain in effect until all of the equity interests in Zhuhai Kingsoft Cloud have been acquired by Beijing Kingsoft Cloud or its designee.
On July 18, 2018, Mr. Yulin Wang and Ms. Weiqin Qiu entered into an exclusive purchase option agreement with Yunxiang Zhisheng and Kingsoft Cloud Information, which was later amended and supplemented on November 29, 2019 and July 15, 2022, and contains terms substantially similar to the exclusive purchase option agreement described above. With the change of the shareholding structure of Kingsoft Cloud Information, where Mr. Tao Zou replaced Mr. Yulin Wang as a registered shareholder of Kingsoft Cloud Information, the original exclusive purchase option agreement entered into among Mr. Yulin Wang, Ms. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information was terminated on August 24, 2022. On the same day, a new exclusive purchase option agreement with substantially the same terms was entered into among Mr. Tao Zou, Ms. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information.
Shareholder Voting Right Trust Agreement
Ms. Weiqin Qiu and Kingsoft Digital, the shareholders of Zhuhai Kingsoft Cloud, entered into a shareholder voting right trust agreement with Beijing Kingsoft Cloud and Zhuhai Kingsoft Cloud on June 20, 2014, which was later amended and supplemented on November 29, 2019. Under the shareholder voting right trust agreement, Ms. Weiqin Qiu and Kingsoft Digital agreed to irrevocably entrust a person designated by Beijing Kingsoft Cloud to represent them to exercise all the voting rights and other shareholders’ rights to which they are entitled as shareholders of Zhuhai Kingsoft Cloud. The shareholder voting right trust agreement shall remain effective from the date of such agreement for as long as Ms. Weiqin Qiu and Kingsoft Digital remain the shareholders of Zhuhai Kingsoft Cloud, unless Beijing Kingsoft Cloud otherwise decides to terminate or amend this agreement.
On July 18, 2018, Mr. Yulin Wang and Ms. Weiqin Qiu entered into a shareholder voting right trust agreement with Yunxiang Zhisheng and Kingsoft Cloud Information, which was later amended and supplemented on November 29, 2019 and July 15, 2022, and contains terms substantially similar to the shareholder voting right trust agreement described above. With the change of the shareholding structure of Kingsoft Cloud Information, where Mr. Tao Zou replaced Mr. Yulin Wang as a registered shareholder of Kingsoft Cloud Information, the original shareholder voting right trust agreement entered into among Mr. Yulin Wang, Ms. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information was terminated on August 24, 2022. On the same day, a new shareholder voting right trust agreement with substantially the same terms was entered into among Mr. Tao Zou, Ms. Weiqin Qiu, Yunxiang Zhisheng and Kingsoft Cloud Information.
118
Table of Contents
Spousal Consents
The spouses of individual shareholders of Zhuhai Kingsoft Cloud and Kingsoft Cloud Information have each signed a spousal consent letter. Under the spousal consent letter, the signing spouse unconditionally and irrevocably agreed that the equity interest in Zhuhai Kingsoft Cloud or Kingsoft Cloud Information which is held by and registered under the name of his or her spouse will be disposed of pursuant to the above-mentioned loan agreements, equity pledge agreements, exclusive purchase option agreements and the shareholder voting rights trust agreements. Moreover, the spouse confirmed he or she has no rights, and will not assert in the future any right, over the equity interests in Zhuhai Kingsoft Cloud or Kingsoft Cloud Information held by his or her spouse. In addition, in the event that the spouse obtains any equity interest in Zhuhai Kingsoft Cloud or Kingsoft Cloud Information held by his or her spouse for any reason, he or she agrees to be bound by and sign any legal documents substantially similar to the contractual arrangements entered into by his or her spouse, as may be amended from time to time.
In the opinion of Fangda Partners, our PRC legal counsel:
● the ownership structures of Beijing Kingsoft Cloud, Zhuhai Kingsoft Cloud, Yunxiang Zhisheng and Kingsoft Cloud Information, do not violate any applicable PRC laws, regulations or rules currently in effect; and
● the agreements among Beijing Kingsoft Cloud, Zhuhai Kingsoft Cloud and its shareholders, Yunxiang Zhisheng, and Kingsoft Cloud Information and its shareholders governed by PRC laws, as described above, are valid, binding and enforceable in accordance with their terms and applicable PRC laws, rules and regulations currently in effect, and do not violate any applicable PRC laws, rules or regulations currently in effect.
However, there are substantial uncertainties regarding the interpretation and application of current or future PRC laws and regulations. We have been further advised by our PRC legal counsel that if the PRC government finds that the agreements that establish the structure for operating our value-added telecommunications services and related business do not comply with PRC government restrictions on foreign investment in such businesses, we are likely to be subject to penalties including being prohibited from continuing operations. For a description of the risks related to these contractual arrangements and our corporate structure, please see “Item 3. Key Information—3.D. Risk Factors—Risks Relating to Our Corporate Structure and the Contractual Arrangements.”
Financial Support Undertaking Letter
We executed a financial support undertaking letter addressed to Zhuhai Kingsoft Cloud and Kingsoft Cloud Information, pursuant to which we undertake to provide unlimited financial support to Zhuhai Kingsoft Cloud and Kingsoft Cloud Information to the extent permissible under the applicable PRC laws and regulations, whether or not any operational loss is actually incurred. The form of financial support shall include, but is not limited to, extension of cash, entrusted loans and borrowings. We will not request repayment of the loans or borrowings if Zhuhai Kingsoft Cloud and Kingsoft Cloud Information or their shareholders do not have sufficient funds or are unable to repay.
4.D.Property, Plant and Equipment
Our current principal executive offices are located at Building D, Xiaomi Science and Technology Park, No. 33 Xierqi Middle Road, Haidian District, Beijing, China. We lease properties in Beijing and certain other cities where we operate with an aggregate of approximately 65,542.6 square meters as of December 31, 2025. These facilities currently accommodate our management headquarters, as well as most of our sales and marketing, research and development, and general and administrative activities. We also have two data centers in Beijing and Tianjin, China, to support our business.